CVE-2026-90121: irqchip/gic-v5: Clear per-CPU IRS data on teardown

Published Sep 17, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

irqchip/gic-v5: Clear per-CPU IRS data on teardown

IRS affinity setup publishes an IRS pointer and IAFFID state in the per-CPU data before the remaining IRS initialization can fail. The error path then frees the IRS data without clearing that published state, leaving CPUs associated with freed memory.

On initialization failure and normal IRS teardown, clear the per-CPU IRS association by removing the stale pointer to irsdata. Also invalidate the per-CPU IAFFID state for any CPUs that were tied to the IRS before it was freed.

Affected Software

1 affected component
Linux Linux kernel

Event History

Sep 17, 2026
CVE Published
via MITRE·04:06 PM
Data Sourced
via MITRE·04:06 PM
Description

Frequently Asked Questions

1

Which systems are exposed to this issue?

Systems using the Linux kernel's irqchip/gic-v5 support and IRS affinity setup are exposed when IRS initialization fails or when an IRS is torn down. The issue concerns per-CPU state associated with IRS data.

2

What condition triggers the vulnerability?

IRS affinity setup must publish per-CPU IRS pointer and IAFFID state, followed by an initialization failure, or the IRS must later undergo normal teardown. In those cases, the prior behavior could leave CPUs referencing IRS memory after it had been freed.

3

How can I determine whether a system may already be affected?

Review whether the system has encountered failed IRS initialization or IRS teardown while using irqchip/gic-v5. Affected behavior leaves stale per-CPU irs_data pointers and IAFFID state associated with freed IRS data.

4

What is the relevant remediation?

Apply the Linux kernel fix that clears the per-CPU IRS association and invalidates IAFFID state for CPUs tied to an IRS before its data is freed. The provided stable references identify fixes for this behavior.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203