CVE-2026-64461
CVE CVE-2026-64461EUVD EUVD-2026-48805Published 2026-07-25T08:51:28.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: PCI: mediatek: Fix IRQ domain leak when port fails to enable When mtk_pcie_enable_port() fails, mtk_pcie_port_free() removes the port from pcie->ports and frees the port structure. However, the IRQ domains set up earlier by mtk_pcie_init_irq_domain() are never freed. Fix this by refactoring mtk_pcie_irq_teardown() into a per-port helper, mtk_pcie_irq_teardown_port(), and calling it from mtk_pcie_setup() when mtk_pcie_enable_port() fails. Since the IRQ teardown must only happen in the probe error path (during resume, child devices may have active MSI mappings and the NOIRQ context prohibits sleeping locks), mtk_pcie_enable_port() is changed to return an error code so callers can distinguish the two paths and act accordingly. This issue was reported by Sashiko while reviewing the EcoNet EN7528 SoC support series.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 0; b099631df160ec608cd6147f4d20a8042567a5b8 <ce52e494a7555bdae1d990a2654fd7547ef6d986; b099631df160ec608cd6147f4d20a8042567a5b8 <df77314b3bedbd9ad5d6f0682f98b99e3c5f7e2e; b099631df160ec608cd6147f4d20a8042567a5b8 <1fbe8972a39548a633d06d7b03a01b7b119a2c12; patch: 6.1.178; patch: 6.12.97; patch: 7.2-rc1; patch: 5.15.212; patch: 7.1.4; 4.14; b099631df160ec608cd6147f4d20a8042567a5b8 <e23da72ef202654a7d5269885c4fa39a8404db76; b099631df160ec608cd6147f4d20a8042567a5b8 <fe8c701a53c2816cd82301f66c671d952003c1b0; patch: 6.6.145; b099631df160ec608cd6147f4d20a8042567a5b8 <6e6a529d6f779413379b4404c9ef6a36c0337225; b099631df160ec608cd6147f4d20a8042567a5b8 <f865a57896bd92d7662eb2818d8f48872e2cbbc7; b099631df160ec608cd6147f4d20a8042567a5b8 <ec7c05eed47d8b15c45380aee7ca168a82e15035; patch: 5.10.261; patch: 6.18.39
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.