Use-after-free in Linux kernel - CVE-2026-64462
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a stale pointer in the altera pcie irq handler teardown logic in drivers/pci/controller/pcie-altera.c when handling a probe failure after irq setup. A local user can trigger a driver probe failure to cause a denial of service.
The issue occurs because the chained IRQ handler and INTx IRQ domain can remain configured after probe failure while the associated devm-managed host bridge storage is released.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-64462
linux (Debian package) - update to 6.12.100-1
External References
- https://git.kernel.org/stable/c/09c43b7b7d29c6fadb27f32cdf7f3bb6598befa9
- https://git.kernel.org/stable/c/0db9aa9ec51be0a0ffdcdfd9af2b7bf3aeb7911a
- https://git.kernel.org/stable/c/6864c789b570e57f932847fa83f6b56917182d73
- https://git.kernel.org/stable/c/7a94138caeb27f3c49c1dbd93bf422098925bb28
- https://git.kernel.org/stable/c/99fc088d6cc6890ae35fa2f29c50ebe027844c20
- https://git.kernel.org/stable/c/9cf0cc481e1645ec65e61486ae41c486c59781cb
- https://git.kernel.org/stable/c/a25bfa2a6665a1d77324d4a609e7513b87680227
- https://git.kernel.org/stable/c/af7cf5d56d7d57c4fbfdb7b5b693790f331b07b7