CVE-2026-72324

UnknownEPSS 0.21%

Last modified

CVE-2026-72324 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: gpio: mvebu: free generic chips on unbind irq_alloc_domain_generic_chips() allocates generic chip data that must be freed via irq_domain_remove_generic_chips(). The devres action mvebu_gpio_remove_irq_domain() only called irq_domain_remove(), which only frees the generic chips if IRQ_DOMAIN_FLAG_DESTROY_GC is set. Call irq_domain_remove_generic_chips() explicitly before irq_domain_remove() instead.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: gpio: mvebu: free generic chips on unbind irq_alloc_domain_generic_chips() allocates generic chip data that must be freed via irq_domain_remove_generic_chips(). The devres action mvebu_gpio_remove_irq_domain() only called irq_domain_remove(), which only frees the generic chips if IRQ_DOMAIN_FLAG_DESTROY_GC is set. Call irq_domain_remove_generic_chips() explicitly before irq_domain_remove() instead.

Metrics

EPSS Probability
0.21%

11.4th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 812d47889a8e418d7bea9bec383581a34c19183e, < 3649b04f86b95243fa0c845695051455fa2ba40b; >= 812d47889a8e418d7bea9bec383581a34c19183e, < 3bfcce441c552133adeeb99c294d0ce8a62612ef; >= 812d47889a8e418d7bea9bec383581a34c19183e, < d73e4d790db611da7439e78a6ab6cb32e7885ab8; >= 812d47889a8e418d7bea9bec383581a34c19183e, < b11c513ad943f35cf5e8007d3a56279c79b7ed4b; f0cde54863da281cec1ed85497b4ec58d29c1460; 7a9239fd04802ee6ddf82d211cff3ee7df9c473a; >= 3.16.40, < 3.17; >= 4.8.9, < 4.9
LinuxLinux4.9

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-72324?
In the Linux kernel, the following vulnerability has been resolved: gpio: mvebu: free generic chips on unbind irq_alloc_domain_generic_chips() allocates generic chip data that must be freed via irq_domain_remove_generic_chips(). The devres action mvebu_gpio_remove_irq_domain() only called irq_domain_remove(), which only frees the generic chips if IRQ_DOMAIN_FLAG_DESTROY_GC is set. Call irq_domain_remove_generic_chips() explicitly before irq_domain_remove() instead.
How severe is CVE-2026-72324?
Severity scoring for CVE-2026-72324 is pending analysis. The EPSS model estimates a 0.21% probability of exploitation in the next 30 days.
How do I fix CVE-2026-72324?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-72324?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST