CVE-2026-93072

medium

Description

In the Linux kernel, the following vulnerability has been resolved: irqchip/renesas-irqc: Fix generic interrupt chip leak on remove The driver allocates domain generic chips probe. However, on driver removal, the generic chips are not automatically freed when the interrupt domain is removed because the domain flags do not include IRQ_DOMAIN_FLAG_DESTROY_GC. This causes both the domain generic chips structure and the associated generic chips to be leaked. Additionally, the generic chips remain on the global list and may later be accessed by generic interrupt chip suspend, resume, or shutdown callbacks after the driver has been removed, potentially resulting in a use-after-free and kernel crash. Fix the resource leak by setting IRQ_DOMAIN_FLAG_DESTROY_GC on the interrupt domain; this lets the interrupt domain core automatically release all generic chips when irq_domain_remove() is invoked, removing the need for manual cleanup calls in error paths and remove callback.

References

https://git.kernel.org/stable/c/9acc996cb2e8477ae81bd7c067fec15202d6bc89

https://git.kernel.org/stable/c/7c614f83301d464e2fb498d63552490d137ea10d

https://git.kernel.org/stable/c/616dd89d81ad9a3cf1cfff4088a4c43e4e00d6ba

https://git.kernel.org/stable/c/4bf7614d048434326081eef0ebef33cb77fe2ffc

https://git.kernel.org/stable/c/3d39757ef791f90028da9c8b7c1fbbb497237e58

Details

Source: Mitre, NVD

Published: 2026-09-17

Updated: 2026-09-17

Risk Information

CVSS v2

Base Score: 6.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.002