{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  PCI: plda: Fix use-after-free of event IRQs during teardown  plda_pcie_irq_domain_deinit() removes pcie-\u003eevent_domain via irq_domain_remove(), but the per-event IRQs mapped from that domain are requested with devm_request_irq() in plda_init_interrupts(). The actual free_irq() for a devm-managed IRQ is deferred by devres until after the calling probe()/remove() function returns.  This means irq_domain_remove() can free the domain's internal data before the deferred free_irq() for IRQs still mapped into it has run. When devres later processes that deferred cleanup, it can end up dereferencing the already-freed domain.  Free each event IRQ explicitly with devm_free_irq() before removing the domain. This triggers the free immediately and removes the IRQ from the devres tracking list, so devres will not attempt to free it a second time later.  Also dispose of the event, INTx, and MSI IRQ mappings with irq_dispose_mapping() before their owning domains are removed.  Finally, guard the calls to irq_set_chained_handler_and_data() for pcie-\u003eirq, pcie-\u003emsi_irq, and pcie-\u003eintx_irq so they only run when those fields hold a valid (\u003e0) IRQ number.  This is a pre-existing issue, flagged by automated review during work on an earlier, unrelated patch to this driver.  Build-tested and boot-tested on StarFive VisionFive v1.2A board",
  "id": "DEBIAN-CVE-2026-89455",
  "modified": "2026-09-12T08:47:27.526773404Z",
  "published": "2026-09-11T20:19:26.220Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-89455"
    }
  ],
  "upstream": [
    "CVE-2026-89455"
  ]
}