CVE-2026-93072

Source
https://cve.org/CVERecord?id=CVE-2026-93072
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93072.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93072
Downstream
Published
2026-09-17T16:10:55Z
Modified
2026-09-18T03:48:43Z
Summary
irqchip/renesas-irqc: Fix generic interrupt chip leak on remove
Details

In the Linux kernel, the following vulnerability has been resolved:

irqchip/renesas-irqc: Fix generic interrupt chip leak on remove

The driver allocates domain generic chips probe. However, on driver removal, the generic chips are not automatically freed when the interrupt domain is removed because the domain flags do not include IRQ_DOMAIN_FLAG_DESTROY_GC.

This causes both the domain generic chips structure and the associated generic chips to be leaked. Additionally, the generic chips remain on the global list and may later be accessed by generic interrupt chip suspend, resume, or shutdown callbacks after the driver has been removed, potentially resulting in a use-after-free and kernel crash.

Fix the resource leak by setting IRQ_DOMAIN_FLAG_DESTROY_GC on the interrupt domain; this lets the interrupt domain core automatically release all generic chips when irq_domain_remove() is invoked, removing the need for manual cleanup calls in error paths and remove callback.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93072.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
99c221df33fbfa1b30e15dee879eb0a9ae1be353
Fixed
3d39757ef791f90028da9c8b7c1fbbb497237e58
Fixed
4bf7614d048434326081eef0ebef33cb77fe2ffc
Fixed
9acc996cb2e8477ae81bd7c067fec15202d6bc89
Fixed
7c614f83301d464e2fb498d63552490d137ea10d
Fixed
616dd89d81ad9a3cf1cfff4088a4c43e4e00d6ba

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93072.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.4.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93072.json"