Improper access control in Linux kernel - CVE-2026-90258
Published: September 18, 2026
Vulnerability identifier: #VU151220
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-90258
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to change the direction of active IRQ pins to output.
The vulnerability exists due to improper access control in the Airoha GPIO IRQ chip when configuring active IRQ pins. A local user can issue a GPIO reconfiguration request to change the direction of active IRQ pins to output.
Affected software
Linux kernel
How to mitigate CVE-2026-90258
Install security update from vendor's repository.