CVE-2026-72384

Source
https://cve.org/CVERecord?id=CVE-2026-72384
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72384.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72384
Downstream
Published
2026-08-15T05:56:15.410Z
Modified
2026-08-16T03:48:40.965725149Z
Summary
irqchip/ts4800: Fix missing chained handler cleanup on remove
Details

In the Linux kernel, the following vulnerability has been resolved:

irqchip/ts4800: Fix missing chained handler cleanup on remove

The driver installs a chained handler for the parent interrupt during probe using irqsetchainedhandlerand_data(), but the remove function does not clear this handler. This leaves a dangling handler that may be called when the parent interrupt fires after the driver has been removed, potentially accessing freed memory and causing a kernel crash.

Additionally, the parentirq obtained via irqofparseand_map() is not stored, making it inaccessible in the remove function. Moreover, interrupt mappings created during probe are not properly disposed.

Fix this by:

  • Saving parent_irq in probe
  • Clearing the chained handler with NULL in ts4800icremove()
  • Disposing all IRQ mappings before domain removal to prevent resource leaks
Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72384.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
d01f8633d52e4dac5ee598b87d49fd23346ccfd6
Fixed
b5b2b2cb6a91908e6c23958c9ce6d5ba2fdb686c
Fixed
e6b674dc341c6add7d85bec2ec22caf1aad35795
Fixed
3f31f49afffa169cd01e6c37568c4df3eb1051af
Fixed
4e8d498d32b6c67d73bb8b317ff316ff37897a3e
Fixed
9ed0dca2aa05908b33ecf0bb15c7953947529542
Fixed
98bf7e54cec07d514b3575c11896a8b12d50ecc4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72384.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.5.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72384.json"