Missing Release of Resource after Effective Lifetime in Linux kernel - CVE-2026-93145
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local privileged user to cause a denial of service.
The vulnerability exists due to failure to release generic power-domain structures in gdsc_unregister() when performing a provider unbind and rebind cycle. A local privileged user can trigger a provider unbind and rebind cycle to cause a denial of service.
Affected software
How to mitigate CVE-2026-93145
External References
- https://git.kernel.org/stable/c/0f4733f5fc6b6b62750619f30c18730922a1dbdb
- https://git.kernel.org/stable/c/40bd77fa2857ccfa77b885b77d44cea406f24a4c
- https://git.kernel.org/stable/c/418d2f0a32b2a9ceb656a88aa9139408a9b7b517
- https://git.kernel.org/stable/c/6333cbf7e86df9797b342ce64ae7d32ba46d8d10
- https://git.kernel.org/stable/c/6b9228a43963bcd4db92deb467375345132c29b3
- https://git.kernel.org/stable/c/86b23609d5e17a770d03037e53c6a443e742a6e6
- https://git.kernel.org/stable/c/cfe16d993c578f6b17e0171a8dfd68f6fdfcfb24
- https://git.kernel.org/stable/c/f60f495858379dc70e87c6898d761a9db98739ff