irqchip/renesas-irqc: Fix generic interrupt chip leak on remove
Summary
| CVE | CVE-2026-93072 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-17 17:18:01 UTC |
| Updated | 2026-09-17 17:18:01 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: irqchip/renesas-irqc: Fix generic interrupt chip leak on remove The driver allocates domain generic chips probe. However, on driver removal, the generic chips are not automatically freed when the interrupt domain is removed because the domain flags do not include IRQ_DOMAIN_FLAG_DESTROY_GC. This causes both the domain generic chips structure and the associated generic chips to be leaked. Additionally, the generic chips remain on the global list and may later be accessed by generic interrupt chip suspend, resume, or shutdown callbacks after the driver has been removed, potentially resulting in a use-after-free and kernel crash. Fix the resource leak by setting IRQ_DOMAIN_FLAG_DESTROY_GC on the interrupt domain; this lets the interrupt domain core automatically release all generic chips when irq_domain_remove() is invoked, removing the need for manual cleanup calls in error paths and remove callback. |
Risk And Classification
EPSS: 0.002000000 probability, percentile 0.102110000 (date 2026-09-18)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 99c221df33fbfa1b30e15dee879eb0a9ae1be353 3d39757ef791f90028da9c8b7c1fbbb497237e58 git | Not specified |
| CNA | Linux | Linux | affected 99c221df33fbfa1b30e15dee879eb0a9ae1be353 4bf7614d048434326081eef0ebef33cb77fe2ffc git | Not specified |
| CNA | Linux | Linux | affected 99c221df33fbfa1b30e15dee879eb0a9ae1be353 9acc996cb2e8477ae81bd7c067fec15202d6bc89 git | Not specified |
| CNA | Linux | Linux | affected 99c221df33fbfa1b30e15dee879eb0a9ae1be353 7c614f83301d464e2fb498d63552490d137ea10d git | Not specified |
| CNA | Linux | Linux | affected 99c221df33fbfa1b30e15dee879eb0a9ae1be353 616dd89d81ad9a3cf1cfff4088a4c43e4e00d6ba git | Not specified |
| CNA | Linux | Linux | affected 4.4 | Not specified |
| CNA | Linux | Linux | unaffected 4.4 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.157 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.110 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.52 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2.6 7.2.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.3-rc1 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/9acc996cb2e8477ae81bd7c067fec15202d6bc89 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/3d39757ef791f90028da9c8b7c1fbbb497237e58 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/4bf7614d048434326081eef0ebef33cb77fe2ffc | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/7c614f83301d464e2fb498d63552490d137ea10d | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/616dd89d81ad9a3cf1cfff4088a4c43e4e00d6ba | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.