Answer in brief
CVE-2026-92481 records a Unknown severity vulnerability in pinctrl: mediatek: free EINT resources on unbind. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=e46df235b4e605aa4e7609a27c118a1cccd4ff9a <23252bc1cd9a58a039c9b1ae77b22d2b33da48e9 || >=e46df235b4e605aa4e7609a27c118a1cccd4ff9a <903a7cdf63a81d3738594c5bd1b5955f58fda427 || >=e46df235b4e605aa4e7609a27c118a1cccd4ff9a <51552c8c60d3b1fecc062eab2d8cfeaa1cb339dd || >=e46df235b4e605aa4e7609a27c118a1cccd4ff9a <7f6d898179ca4771ee602bdad4246c3952af83eb || >=e46df235b4e605aa4e7609a27c118a1cccd4ff9a <e06785cba7f86d72abd531058b1a82d6952a7346 || >=e46df235b4e605aa4e7609a27c118a1cccd4ff9a <88292b7103d260e3e606eb3bb2794060a5fde48e | 23252bc1cd9a58a039c9b1ae77b22d2b33da48e9, 903a7cdf63a81d3738594c5bd1b5955f58fda427, 51552c8c60d3b1fecc062eab2d8cfeaa1cb339dd, 7f6d898179ca4771ee602bdad4246c3952af83eb, e06785cba7f86d72abd531058b1a82d6952a7346, 88292b7103d260e3e606eb3bb2794060a5fde48e |
| Linux/Linuxgeneric | 4.18 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: pinctrl: mediatek: free EINT resources on unbind mtk_eint_do_init() creates an IRQ domain, populates it with a mapping for every EINT line and installs a chained handler on the parent interrupt, but none of these are ever released. This was harmless while the drivers were built-in, but now that they can be built as modules and unbound/rmmod'd it leaves behind a dangling IRQ domain, interrupt mappings whose chip data points at freed memory, and a chained handler that keeps firing into that freed data. The plain allocations in mtk_eint_do_init() already use the device-managed devm_*() helpers, so tear the remaining resources down the same way: register a devm action that detaches the chained handler, waits for any in-flight handler to finish, disposes of the per-line mappings and removes the IRQ domain. This mirrors the device-managed lifecycle adopted for the GPIO chip and keeps the whole EINT setup self-cleaning on unbind.
Quoted source text, attributed separately from HOL analysis.