CVE-2026-63862

Source
https://cve.org/CVERecord?id=CVE-2026-63862
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-63862.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-63862
Downstream
Published
2026-07-19T14:04:49.380Z
Modified
2026-07-21T03:47:29.200639609Z
Summary
PCI: mediatek-gen3: Prevent leaking IRQ domains when IRQ not found
Details

In the Linux kernel, the following vulnerability has been resolved:

PCI: mediatek-gen3: Prevent leaking IRQ domains when IRQ not found

In mtkpciesetup_irq(), the IRQ domains are allocated before the controller's IRQ is fetched. If the latter fails, the function directly returns an error, without cleaning up the allocated domains.

Hence, reverse the order so that the IRQ domains are allocated after the controller's IRQ is found.

This was flagged by Sashiko during a review of "[PATCH v6 0/7] PCI: mediatek-gen3: add power control support".

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63862.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
814cceebba9b7d1306b8d49587ffb0e81f7b73af
Fixed
abd3c1927d33766aef39c4640880e3d2637429c2
Fixed
07a5ecb94768cbf76fe659e9924000e9ced0c8a6
Fixed
946b31b5a699a2760ee52af0055e5ebf29c5f4cb
Fixed
0a2d60edc3e57c9512e239ebdfd12204d3368560
Fixed
215d4273347b9010a9deae378b0df79c163f707d
Fixed
5573c44cb3fd01a9f62d569ae9ac870ef5f0e0ba

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-63862.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.13.0
Fixed
6.1.175
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.141
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.91
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.33
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.10

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-63862.json"