SB20260918385 - Improper resource shutdown or release in Linux kernel phy sunplus driver
Published: September 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper resource shutdown or release (CVE-ID: CVE-2026-90287)
CWE-ID: CWE-404 - Improper Resource Shutdown or Release
CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to leak clock and reset resources.
The vulnerability exists due to improper resource shutdown or release in sp_uphy_init() when handling USB PHY initialization failures. A local user can trigger a USB PHY initialization failure to leak clock and reset resources.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1489b694b1f3265cd5363100642a22190033f4b0
- https://git.kernel.org/stable/c/1fce81a40e3b3ec6b4f52e278d5c2bde79b25939
- https://git.kernel.org/stable/c/3a7dcbe3112aef3505beae4f982331a00326217c
- https://git.kernel.org/stable/c/5acdc4d5b58bd0730824938db79b5f08ef996d9c
- https://git.kernel.org/stable/c/8b2683bc4cc18c581b7cd24f227cbe61abca7f4d
- https://git.kernel.org/stable/c/d8856bfe6d00c21c4c0ba689cb6c9e30ceaccb8f