Improper resource shutdown or release in Linux kernel - CVE-2026-90287
Published: September 18, 2026
Vulnerability identifier: #VU151198
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-90287
CWE-ID: CWE-404
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to leak clock and reset resources.
The vulnerability exists due to improper resource shutdown or release in sp_uphy_init() when handling USB PHY initialization failures. A local user can trigger a USB PHY initialization failure to leak clock and reset resources.
Affected software
Linux kernel
How to mitigate CVE-2026-90287
Install security update from vendor's repository.
External References
- https://git.kernel.org/stable/c/1489b694b1f3265cd5363100642a22190033f4b0
- https://git.kernel.org/stable/c/1fce81a40e3b3ec6b4f52e278d5c2bde79b25939
- https://git.kernel.org/stable/c/3a7dcbe3112aef3505beae4f982331a00326217c
- https://git.kernel.org/stable/c/5acdc4d5b58bd0730824938db79b5f08ef996d9c
- https://git.kernel.org/stable/c/8b2683bc4cc18c581b7cd24f227cbe61abca7f4d
- https://git.kernel.org/stable/c/d8856bfe6d00c21c4c0ba689cb6c9e30ceaccb8f