{"id":"CVE-2026-89455","title":"kernel: PCI: plda: Fix use-after-free of event IRQs during teardown (CVE-2026-89455)","summary":"A flaw was found in the Linux kernel's PCI PLDA driver. During the teardown of Interrupt Request (IRQ) domains, the system can attempt to access memory that has already been freed. This 'use-after-free' vulnerability occurs because the dom…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-825","vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","affected":["enterprise_linux 10"],"published":"2026-09-11","updated":"2026-09-18","sourceUpdated":"2026-09-18T19:58:26+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89455.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89455.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89455"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532263"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89455"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89455"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89455.mbox"},{"url":"https://git.kernel.org/stable/c/01c2f0c66bd1f892db9c6e82976da6b463cc4427"},{"url":"https://git.kernel.org/stable/c/1d0159e139261996a3ca21798d9114aab2124d3c"},{"url":"https://git.kernel.org/stable/c/26b73bae01d6eb81a4a38f36101812f20b2639de"},{"url":"https://git.kernel.org/stable/c/e3589ca5f2e6477774753a2202c21509428d4701"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.002,"epssPercentile":0.10104,"ingestedAt":"2026-09-14T00:35:28.531Z","slug":"CVE-2026-89455","body":"## Overview\n\nA flaw was found in the Linux kernel's PCI PLDA driver. During the teardown of Interrupt Request (IRQ) domains, the system can attempt to access memory that has already been freed. This 'use-after-free' vulnerability occurs because the domain's internal data is released before all associated IRQs are properly deallocated. This can lead to system instability or crashes.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10 · no fix planned: Red Hat Enterprise Linux 10 · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89455.json)\n\n**kernel: PCI: plda: Fix use-after-free of event IRQs during teardown** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-18.\n\nAffected:\n\n- Red Hat Enterprise Linux 10\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 10\n\nNot affected:\n\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nFix deferred","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":206993,"id":"CVE-2026-89455","ts":1789749735801,"field":"cvss","old":"4.1","new":"5.5"},{"seq":204033,"id":"CVE-2026-89455","ts":1789490231132,"field":"cvss","old":null,"new":"4.1"},{"seq":204032,"id":"CVE-2026-89455","ts":1789490231132,"field":"severity","old":"none","new":"medium"},{"seq":147484,"id":"CVE-2026-89455","ts":1789270211090,"field":"cvss","old":null,"new":"4.1"},{"seq":147483,"id":"CVE-2026-89455","ts":1789270211090,"field":"severity","old":"none","new":"medium"},{"seq":109234,"id":"CVE-2026-89455","ts":1789183731082,"field":"cvss","old":null,"new":"4.1"},{"seq":109233,"id":"CVE-2026-89455","ts":1789183731082,"field":"severity","old":"none","new":"medium"}]}