SB20260727100 - Use-after-free in Linux kernel pci controller driver
Published: July 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-64462)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a stale pointer in the altera pcie irq handler teardown logic in drivers/pci/controller/pcie-altera.c when handling a probe failure after irq setup. A local user can trigger a driver probe failure to cause a denial of service.
The issue occurs because the chained IRQ handler and INTx IRQ domain can remain configured after probe failure while the associated devm-managed host bridge storage is released.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/09c43b7b7d29c6fadb27f32cdf7f3bb6598befa9
- https://git.kernel.org/stable/c/0db9aa9ec51be0a0ffdcdfd9af2b7bf3aeb7911a
- https://git.kernel.org/stable/c/6864c789b570e57f932847fa83f6b56917182d73
- https://git.kernel.org/stable/c/7a94138caeb27f3c49c1dbd93bf422098925bb28
- https://git.kernel.org/stable/c/99fc088d6cc6890ae35fa2f29c50ebe027844c20
- https://git.kernel.org/stable/c/9cf0cc481e1645ec65e61486ae41c486c59781cb
- https://git.kernel.org/stable/c/a25bfa2a6665a1d77324d4a609e7513b87680227
- https://git.kernel.org/stable/c/af7cf5d56d7d57c4fbfdb7b5b693790f331b07b7