Ad

CVE-2026-89455

NONE EPSS 0.21%
Обновлено 11 сентября 2026
Linux
Параметр Значение
Поставщик Linux
Публичный эксплойт Нет

В ядре Linux устранена следующая уязвимость: PCI: plda: исправлено использование IRQ после освобождения событий во время отключения. plda_pcie_irq_domain_deinit() удаляет pcie->event_domain через irq_domain_remove(), но IRQ для каждого события, сопоставленные с этим доменом запрашиваются с помощью devm_request_irq() в plda_init_interrupts(). фактическая функция free_irq() для IRQ, управляемого devm, откладывается devres до тех пор, пока после возврата вызывающей функцииprobe()/remove(). Это означает, что irq_domain_remove() может освободить внутренние данные домена. до того, как будет запущена отложенная функция free_irq() для IRQ, все еще сопоставленных с ней. Когда последующие процессы разработают отложенную очистку, это может закончиться разыменование уже освобожденного домена.

Освободите каждое событие IRQ явно с помощью devm_free_irq() перед удалением. домен. Это немедленно активирует освобождение и удаляет IRQ. из списка отслеживания девреса, поэтому деврес не будет пытаться освободить его второй раз позже. Также удалите сопоставления событий, INTx и MSI IRQ с помощью irq_dispose_mapping() до удаления принадлежащих им доменов.

Наконец, защитите вызовы irq_set_chained_handler_and_data() для pcie->irq, pcie->msi_irq и pcie->intx_irq, поэтому они запускаются только тогда, когда эти поля содержат действительный (>0) номер IRQ. Это уже существующая проблема, отмеченная автоматической проверкой во время работы. в более раннем, несвязанном патче к этому драйверу. Протестировано при сборке и загрузке на плате StarFive VisionFive v1.2A.

Показать оригинальное описание (EN)

In the Linux kernel, the following vulnerability has been resolved: PCI: plda: Fix use-after-free of event IRQs during teardown plda_pcie_irq_domain_deinit() removes pcie->event_domain via irq_domain_remove(), but the per-event IRQs mapped from that domain are requested with devm_request_irq() in plda_init_interrupts(). The actual free_irq() for a devm-managed IRQ is deferred by devres until after the calling probe()/remove() function returns. This means irq_domain_remove() can free the domain's internal data before the deferred free_irq() for IRQs still mapped into it has run. When devres later processes that deferred cleanup, it can end up dereferencing the already-freed domain. Free each event IRQ explicitly with devm_free_irq() before removing the domain. This triggers the free immediately and removes the IRQ from the devres tracking list, so devres will not attempt to free it a second time later. Also dispose of the event, INTx, and MSI IRQ mappings with irq_dispose_mapping() before their owning domains are removed. Finally, guard the calls to irq_set_chained_handler_and_data() for pcie->irq, pcie->msi_irq, and pcie->intx_irq so they only run when those fields hold a valid (>0) IRQ number. This is a pre-existing issue, flagged by automated review during work on an earlier, unrelated patch to this driver. Build-tested and boot-tested on StarFive VisionFive v1.2A board