Improper control of a resource through its lifetime in Linux kernel - CVE-2026-90362
Published: September 25, 2026
Vulnerability details
The vulnerability allows a local user to cause the DSI link clock to run without necessary power backing.
The vulnerability exists due to improper power-state management in dsi_link_clk_disable_6g() when disabling DSI link clocks. A local user can trigger the DSI link clock disable path to cause the DSI link clock to run without necessary power backing.
Affected software
How to mitigate CVE-2026-90362
External References
- https://git.kernel.org/stable/c/00008e6f544c2d480f920ab1e593a46cfb87cead
- https://git.kernel.org/stable/c/06b7ba206561619bb34116f49e0ef26b867ce3aa
- https://git.kernel.org/stable/c/27e181c185194baf5c1ef18bbff1fc3bc283ef21
- https://git.kernel.org/stable/c/393b43cc12c95f3d2762a06f799807313029032e
- https://git.kernel.org/stable/c/5c3e537db05021c93ea40a46bd0c50eee2f30f87
- https://git.kernel.org/stable/c/83bc4eab83ae5ab88d410148a2e73e09e6f21c04
- https://git.kernel.org/stable/c/bc1df05cccdb4f08aa42e736b54d265c6c11a45b
- https://git.kernel.org/stable/c/d3e8355a63cead3dedaa52f46cd1ee9796fdc7a8