SB20260918407 - Improper access control in Linux kernel pinctrl mediatek driver



SB20260918407 - Improper access control in Linux kernel pinctrl mediatek driver

Published: September 18, 2026

Security Bulletin ID SB20260918407
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper access control (CVE-ID: CVE-2026-90258)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to change the direction of active IRQ pins to output.

The vulnerability exists due to improper access control in the Airoha GPIO IRQ chip when configuring active IRQ pins. A local user can issue a GPIO reconfiguration request to change the direction of active IRQ pins to output.


Remediation

Install update from vendor's website.