CVE-2026-89769
Received Received - Intake

IRQ Leak in NXP PIT Clocksource Driver

Vulnerability report for CVE-2026-89769, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-13

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: clocksource/drivers/nxp-pit: Fix IRQ leak on cpuhp_setup_state error path When cpuhp_setup_state fails after pit_clockevent_per_cpu_init has successfully called request_irq, the error handling jumps directly to out_pit_clocksource_unregister without freeing the registered IRQ. This leaks the IRQ line and, since kfree(pit) follows, leaves a dangling pointer registered as the interrupt handler's dev_id, potentially leading to a use-after-free if the IRQ fires afterwards. Fix it by calling pit_clockevent_per_cpu_exit to properly release the IRQ before falling through to the existing cleanup chain.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-13
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Linux kernel vulnerability where an IRQ (interrupt request) is not properly freed when an error occurs during CPU hotplug state setup. The issue happens in the NXP PIT (Periodic Interrupt Timer) clocksource driver. When a specific setup function fails after requesting an IRQ, the cleanup process skips freeing that IRQ, leading to a resource leak. Additionally, a dangling pointer may remain, which could cause a use-after-free if the IRQ triggers later.

Detection Guidance

This vulnerability is specific to the Linux kernel's NXP PIT clocksource driver and does not have network-based detection methods. Detection requires checking kernel logs for IRQ-related errors or inspecting the driver's initialization state. Use commands like dmesg | grep -i pit or journalctl -k | grep -i pit to review kernel logs for IRQ leaks or failed cpuhp_setup_state calls.

Impact Analysis

This vulnerability could lead to system instability or crashes if the leaked IRQ triggers a use-after-free condition. It may cause unexpected behavior, kernel panics, or security issues due to improper resource management. Systems relying on the NXP PIT clocksource driver could experience these problems.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards. It is a Linux kernel IRQ leak issue that could lead to system instability or crashes but does not involve data breaches or unauthorized access to sensitive information.

Mitigation Strategies

Apply the kernel patch that fixes the IRQ leak in the NXP PIT driver. Update your Linux kernel to a version containing the fix. If immediate patching is not possible, disable the NXP PIT clocksource driver by adding clocksource=pit to the kernel command line during boot.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89769. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart