SB20260918407 - Improper access control in Linux kernel pinctrl mediatek driver
Published: September 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper access control (CVE-ID: CVE-2026-90258)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to change the direction of active IRQ pins to output.
The vulnerability exists due to improper access control in the Airoha GPIO IRQ chip when configuring active IRQ pins. A local user can issue a GPIO reconfiguration request to change the direction of active IRQ pins to output.
Remediation
Install update from vendor's website.