CVE-2026-89455Medium· 5.5▾ SunlitA flaw was found in the Linux kernel's PCI PLDA driver. During the teardown of Interrupt Request (IRQ) domains, the system can attempt to access memory that has already been freed. This 'use-after-free' vulnerability occurs because the dom…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
— → 4.1
none → medium
— → 4.1
none → medium
— → 4.1
none → medium
Last analysed / modified upstream
4.1 → 5.5
A flaw was found in the Linux kernel's PCI PLDA driver. During the teardown of Interrupt Request (IRQ) domains, the system can attempt to access memory that has already been freed. This 'use-after-free' vulnerability occurs because the domain's internal data is released before all associated IRQs are properly deallocated. This can lead to system instability or crashes.
kernel: PCI: plda: Fix use-after-free of event IRQs during teardown — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-18.
Affected:
No fix planned:
Not affected:
Fix deferred
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-89668High· 7.0kernel: nfsd: move nfsd_debugfs_init() after nfsd4_init_slabs() in init_nfsd() (CVE-2026-89668)
CVE-2026-89670High· 7.0kernel: nfsd: hold rcu across localio cmpxchg retry (CVE-2026-89670)
CVE-2026-89689High· 7.0kernel: nfsd: don't free session slots that are still in use (CVE-2026-89689)
CVE-2026-89747High· 7.0kernel: tracing: Fix use-after-free in trace_pipe read on sub-buffer order change (CVE-2026-89747)
CVE-2026-89769Medium· 5.5kernel: clocksource/drivers/nxp-pit: Fix IRQ leak on cpuhp_setup_state error path (CVE-2026-89769)
CVE-2026-89469Medium· 5.5kernel: power: supply: lp8727: fix use-after-free in lp8727_release_irq() (CVE-2026-89469)