SB2026091721 - Improper resource shutdown or release in Linux kernel iio dac driver
Published: September 17, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper resource shutdown or release (CVE-ID: CVE-2026-89936)
CWE-ID: CWE-404 - Improper Resource Shutdown or Release
CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to leave the Vcc regulator enabled indefinitely.
The vulnerability exists due to improper resource shutdown or release in m62332_set_value() when writing successive non-zero values to a channel before writing zero. A local user can write successive non-zero values to a channel before writing zero to leave the Vcc regulator enabled indefinitely.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/08ac8d2976d57aa943d64e351c4d0bd8bb0c6de9
- https://git.kernel.org/stable/c/1d3a7d7dd3adee19e00be2b2237140f0fe169484
- https://git.kernel.org/stable/c/9263b9ad968a563337a60e0eb66e35186e1faf9a
- https://git.kernel.org/stable/c/9fe22f563b2a0fdb11fd3711a8c39c023629c08a
- https://git.kernel.org/stable/c/a130404ce0b69ca1438126bd81c1985d3b4d2e6f
- https://git.kernel.org/stable/c/ae18d2d2ef27a4d04fda6e30c23774513dc9be1e
- https://git.kernel.org/stable/c/bac0ed8bee651aa841375edf72c6ab1d10ac80c6
- https://git.kernel.org/stable/c/f5acb824277a97a5210c454872202bf7f08c75d4