SB2026091690 - Improper control of a resource through its lifetime in Linux kernel usb typec driver



SB2026091690 - Improper control of a resource through its lifetime in Linux kernel usb typec driver

Published: September 16, 2026

Security Bulletin ID SB2026091690
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Physical access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-90028)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 0 [CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to trigger an unbalanced regulator disable warning.

The vulnerability exists due to improper regulator enable-state tracking in the hd3ss3220 driver's VBUS regulator control when handling role or ID notifications after another consumer has enabled VBUS. An attacker with physical access can trigger role or ID notifications to trigger an unbalanced regulator disable warning.


Remediation

Install update from vendor's website.