CVE-2026-90123 PUBLISHED

irqchip/ast2700-intc: Avoid allocating in the irq_domain activate() callback

Assigner: Linux
Reserved: 11.09.2026 Published: 17.09.2026 Updated: 17.09.2026

In the Linux kernel, the following vulnerability has been resolved:

irqchip/ast2700-intc: Avoid allocating in the irq_domain activate() callback

The interrupt core calls the irq_domain_activate() callback from __setup_irq() with desc->lock held and interrupts disabled. Both aspeed_intc1_irq_domain_activate() and aspeed_intc0_resolve_route() test a compatible string with fwnode_device_is_compatible().

fwnode_device_is_compatible() invokes fwnode_property_match_string(), which allocates with GFP_KERNEL. That's obviously not possible with interrupts disabled and a raw spinlock held.

Both call sites are only ever handed OF nodes, so use of_device_is_compatible() instead: it walks the property in place and does not allocate.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 07825e41519abb8ac13d6d1c553af47f57775f6b to f2f0da11648616e47419dca93610f6c0d70ec00b (excl.)
  • affected from 07825e41519abb8ac13d6d1c553af47f57775f6b to b76eee9c2157223aa4aac42ceebb563288e078aa (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 7.2 is affected
  • unaffected from 0 to 7.2 (excl.)
  • unaffected from 7.2.6 to 7.2.* (incl.)
  • unaffected from 7.3-rc1 to * (incl.)

References