PT-2026-104851 · Azure Linux · Kernel
Published
2026-09-24
·
Updated
2026-09-24
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
powerpc/xive: propagate IPI init errors to prevent use-after-free
When xive init ipis() fails (e.g. irq domain alloc irqs() fails),
the error path frees the global xive ipis array. However,
xive smp probe() previously ignored this failure and proceeded to
call xive setup cpu ipi(), which dereferences the already-freed
xive ipis pointer -- a use-after-free.
Now that xive smp probe() returns int (previous patch), propagate
the error from xive init ipis() and xive setup cpu ipi() through
xive smp probe(). Check the return value in both pnv smp probe()
and pSeries smp probe() so that IPI setup is aborted cleanly on
failure, avoiding the use-after-free.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kernel