Improper control of a resource through its lifetime in Linux kernel - CVE-2026-90028

 

Improper control of a resource through its lifetime in Linux kernel - CVE-2026-90028

Published: September 16, 2026


Vulnerability identifier: #VU150265
CSH Severity: Low
CVSS v4: 0 [CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-90028
CWE-ID: CWE-664
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker with physical access to trigger an unbalanced regulator disable warning.

The vulnerability exists due to improper regulator enable-state tracking in the hd3ss3220 driver's VBUS regulator control when handling role or ID notifications after another consumer has enabled VBUS. An attacker with physical access can trigger role or ID notifications to trigger an unbalanced regulator disable warning.


Affected software

Linux kernel

How to mitigate CVE-2026-90028

Install security update from vendor's repository.


External References

Related Security Bulletins