Improper locking in Linux kernel - CVE-2026-90208
Published: September 19, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper locking in the Samsung PWM timer driver when handling timer operations in hard interrupt context. A local user can trigger Samsung PWM timer operations to cause a denial of service.
The issue is limited to ARM systems with PREEMPT_RT enabled where the Samsung PWM timer is used as a clock source.