Improper control of a resource through its lifetime in Linux kernel - CVE-2026-90028
Published: September 16, 2026
Vulnerability details
The vulnerability allows an attacker with physical access to trigger an unbalanced regulator disable warning.
The vulnerability exists due to improper regulator enable-state tracking in the hd3ss3220 driver's VBUS regulator control when handling role or ID notifications after another consumer has enabled VBUS. An attacker with physical access can trigger role or ID notifications to trigger an unbalanced regulator disable warning.