SB20260925102 - NULL pointer dereference in Linux kernel regulator driver
Published: September 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2026-93273)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a missing null check and improper resource release in the tps6594_regulator_probe() multiphase configuration loop when processing multiphase regulator configuration. A local user can trigger the loop with a missing buck device node to cause a denial of service.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/28f70e0aa767a8f022c70ed75ecef227dc668121
- https://git.kernel.org/stable/c/4a672bff99f6b58dde419fd12b3a53da137f032d
- https://git.kernel.org/stable/c/68ce4f8223b78f8616ec7f4a02c38988eae627d2
- https://git.kernel.org/stable/c/7fd28093b3effc4f92566466df364622830ec608
- https://git.kernel.org/stable/c/fceac25487b21d6db940d2aed368e465d89cd1f4