CVE-2026-93274EPSS p8.4%
CVE-2026-93274CVE-2026-93274
Description
In the Linux kernel, the following vulnerability has been resolved:
pinctrl: bcm2835: Don't remove an unregistered GPIO chip
If the devm_pinctrl_register() function fails,
bcm2835_pinctrl_probe() calls gpiochip_remove()
before gpiochip_add_data() has registered the GPIO chip.
This means that upon failure the gpio_chip.gpiodev
is NULL resulting in a null pointer dereference
inside the gpiochip_remove() function.
Remove the unnecessary function call to gpiochip_remove().
No GPIO cleanup is required because the GPIO chip
has not yet been registered. Without this change there
is potential for a kernel panic upon registration failure
Scoring
| EPSS | 0.20% probability of exploitation · percentile 8.4% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-24 |