Use-after-free in Linux kernel - CVE-2026-63798

 

Use-after-free in Linux kernel - CVE-2026-63798

Published: July 21, 2026


Vulnerability identifier: #VU138853
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-63798
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in the irq-imgpdc driver when handling interrupts after driver removal. A local user can trigger spurious interrupts that access freed memory to cause a denial of service.

The issue involves dangling chained handlers for peripheral and syswake interrupts, and generic chips may remain reachable by interrupt chip suspend, resume, or shutdown callbacks after the driver has been removed.


Affected software

Linux kernel

How to mitigate CVE-2026-63798

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins