SB2026091690 - Improper control of a resource through its lifetime in Linux kernel usb typec driver
Published: September 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-90028)
CWE-ID: CWE-664 - Improper control of a resource through its lifetime
CVSSv4: 0 [CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to trigger an unbalanced regulator disable warning.
The vulnerability exists due to improper regulator enable-state tracking in the hd3ss3220 driver's VBUS regulator control when handling role or ID notifications after another consumer has enabled VBUS. An attacker with physical access can trigger role or ID notifications to trigger an unbalanced regulator disable warning.
Remediation
Install update from vendor's website.