Back to overview

CVE-2026-63862

Description
In the Linux kernel, the following vulnerability has been resolved: PCI: mediatek-gen3: Prevent leaking IRQ domains when IRQ not found In mtk_pcie_setup_irq(), the IRQ domains are allocated before the controller's IRQ is fetched. If the latter fails, the function directly returns an error, without cleaning up the allocated domains. Hence, reverse the order so that the IRQ domains are allocated after the controller's IRQ is found. This was flagged by Sashiko during a review of "[PATCH v6 0/7] PCI: mediatek-gen3: add power control support".

Metadata

CVE ID
CVE-2026-63862
State
PUBLISHED
Assigner
Linux
Reserved
2026-07-19 07:54 UTC
Published
2026-07-19 14:04 UTC
Last updated
2026-07-19 14:04 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (2)
VendorProductPlatformVersions
Linux Linux 814cceebba9b7d1306b8d49587ffb0e81f7b73af < abd3c1927d33766aef39c4640880e3d2637429c2, 814cceebba9b7d1306b8d49587ffb0e81f7b73af < 07a5ecb94768cbf76fe659e9924000e9ced0c8a6, 814cceebba9b7d1306b8d49587ffb0e81f7b73af < 946b31b5a699a2760ee52af0055e5ebf29c5f4cb, 814cceebba9b7d1306b8d49587ffb0e81f7b73af < 0a2d60edc3e57c9512e239ebdfd12204d3368560 …
Linux Linux 5.13, 0 < 5.13, 6.1.175 ≤ 6.1.*, 6.6.141 ≤ 6.6.* …
Back to overview