CVE-2026-46252
In the Linux kernel, the following vulnerability has been resolved:
regulator: core: fix locking in regulator_resolve_supply() error path
If late enabling of a supply regulator fails in regulator_resolve_supply(), the code currently triggers a lockdep warning:
as the regulator_list_mutex must be held when calling _regulator_put().
To solve this, simply switch to using regulator_put().
While at it, we should also make sure that no concurrent access happens to our rdev while we clear out the supply pointer. Add appropriate locking to ensure that.
While the code in question will be removed altogether in a follow-up commit, I believe it is still beneficial to have this corrected before removal for future reference.
Detalles técnicos trazas, registros y código del informe original
WARNING: drivers/regulator/core.c:2649 at _regulator_put+0x80/0xa0, CPU#6: kworker/u32:4/596
...
Call trace:
_regulator_put+0x80/0xa0 (P)
regulator_resolve_supply+0x7cc/0xbe0
regulator_register_resolve_supply+0x28/0xb8CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 5.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.13%
- Percentil entre todas las CVEs puntuadas: 2
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-667
Referencias
- https://git.kernel.org/stable/c/3b7fffd7a8984a1c009f668765ee7631fd6b87c8
- https://git.kernel.org/stable/c/497330b203d2c59c5ff3fa4c34d14494d7203bc3
- https://git.kernel.org/stable/c/60747114fd2a38739130b715e7b2d40ce848f0be
- https://git.kernel.org/stable/c/a8a2eab1166bc33ee38ca371cff425bdb5681e47
- https://git.kernel.org/stable/c/bde74af8d4466213007bdd42cc85fa72c861dea7
- https://git.kernel.org/stable/c/c66e0db0f37290b53c57994f998bb55590364fd0
- https://git.kernel.org/stable/c/c84860dac7af7dc3c3e3c9ae86d65e222c2f3b0c
- https://git.kernel.org/stable/c/e77357dc2293283fc08a485b1e2e571d91d02622
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-46252",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.5,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "36a1f1b6ddc6d1442424e29548e790633ca39c7b",
"lessThan": "e77357dc2293283fc08a485b1e2e571d91d02622",
"versionType": "git"
},
{
"status": "affected",
"version": "36a1f1b6ddc6d1442424e29548e790633ca39c7b",
"lessThan": "a8a2eab1166bc33ee38ca371cff425bdb5681e47",
"versionType": "git"
},
{
"status": "affected",
"version": "36a1f1b6ddc6d1442424e29548e790633ca39c7b",
"lessThan": "60747114fd2a38739130b715e7b2d40ce848f0be",
"versionType": "git"
},
{
"status": "affected",
"version": "36a1f1b6ddc6d1442424e29548e790633ca39c7b",
"lessThan": "c84860dac7af7dc3c3e3c9ae86d65e222c2f3b0c",
"versionType": "git"
},
{
"status": "affected",
"version": "36a1f1b6ddc6d1442424e29548e790633ca39c7b",
"lessThan": "3b7fffd7a8984a1c009f668765ee7631fd6b87c8",
"versionType": "git"
},
{
"status": "affected",
"version": "36a1f1b6ddc6d1442424e29548e790633ca39c7b",
"lessThan": "bde74af8d4466213007bdd42cc85fa72c861dea7",
"versionType": "git"
},
{
"status": "affected",
"version": "36a1f1b6ddc6d1442424e29548e790633ca39c7b",
"lessThan": "c66e0db0f37290b53c57994f998bb55590364fd0",
"versionType": "git"
},
{
"status": "affected",
"version": "36a1f1b6ddc6d1442424e29548e790633ca39c7b",
"lessThan": "497330b203d2c59c5ff3fa4c34d14494d7203bc3",
"versionType": "git"
}
],
"programFiles": [
"drivers/regulator/core.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.2"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.2",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.260",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.211",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.177",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.144",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.95",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.37",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "6.19.4",
"versionType": "semver",
"lessThanOrEqual": "6.19.*"
},
{
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/regulator/core.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-06-03T18:16:25.797",
"references": [
{
"url": "https://git.kernel.org/stable/c/3b7fffd7a8984a1c009f668765ee7631fd6b87c8",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/497330b203d2c59c5ff3fa4c34d14494d7203bc3",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/60747114fd2a38739130b715e7b2d40ce848f0be",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a8a2eab1166bc33ee38ca371cff425bdb5681e47",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/bde74af8d4466213007bdd42cc85fa72c861dea7",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c66e0db0f37290b53c57994f998bb55590364fd0",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c84860dac7af7dc3c3e3c9ae86d65e222c2f3b0c",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e77357dc2293283fc08a485b1e2e571d91d02622",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-667"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nregulator: core: fix locking in regulator_resolve_supply() error path\n\nIf late enabling of a supply regulator fails in\nregulator_resolve_supply(), the code currently triggers a lockdep\nwarning:\n\n WARNING: drivers/regulator/core.c:2649 at _regulator_put+0x80/0xa0, CPU#6: kworker/u32:4/596\n ...\n Call trace:\n _regulator_put+0x80/0xa0 (P)\n regulator_resolve_supply+0x7cc/0xbe0\n regulator_register_resolve_supply+0x28/0xb8\n\nas the regulator_list_mutex must be held when calling _regulator_put().\n\nTo solve this, simply switch to using regulator_put().\n\nWhile at it, we should also make sure that no concurrent access happens\nto our rdev while we clear out the supply pointer. Add appropriate\nlocking to ensure that.\n\nWhile the code in question will be removed altogether in a follow-up\ncommit, I believe it is still beneficial to have this corrected before\nremoval for future reference."
},
{
"lang": "es",
"value": "En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:\n\nregulator: core: corregir el bloqueo en la ruta de error de regulator_resolve_supply()\n\nSi la habilitación tardía de un regulador de suministro falla en regulator_resolve_supply(), el código actualmente activa una advertencia de lockdep:\n\nADVERTENCIA: drivers/regulator/core.c:2649 at _regulator_put+0x80/0xa0, CPU#6: kworker/u32:4/596\n...\nTraza de llamada:\n _regulator_put+0x80/0xa0 (P)\n regulator_resolve_supply+0x7cc/0xbe0\n regulator_register_resolve_supply+0x28/0xb8\n\nya que el regulator_list_mutex debe mantenerse al llamar a _regulator_put().\n\nPara resolver esto, simplemente cambie a usar regulator_put().\n\nYa que estamos en ello, también deberíamos asegurarnos de que no ocurra ningún acceso concurrente a nuestro rdev mientras borramos el puntero de suministro. Añada un bloqueo apropiado para asegurar eso.\n\nAunque el código en cuestión será eliminado por completo en un commit de seguimiento, creo que sigue siendo beneficioso tener esto corregido antes de la eliminación para futuras referencias."
}
],
"lastModified": "2026-07-22T20:10:00.127",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EACE7ACD-1611-41BF-B757-A23CEC8346ED",
"versionEndExcluding": "6.19.4",
"versionStartIncluding": "4.2.1"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:4.2:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "37D5F2FA-B7D0-4F9D-BC97-F450E5839C7B"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:4.2:rc4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8C5DADE2-2A31-4F65-8A7E-224C02958A81"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:4.2:rc5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "130E1C2A-45DE-4C16-8FFA-06E9C9F7F175"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:4.2:rc6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "78F0CC21-E28A-4B83-B65B-94AB9242F345"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:4.2:rc7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AED16DC6-6364-4B57-92A1-F14F347DADF7"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:4.2:rc8:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "03A4BCF1-5A7D-4E74-948F-134F0E57D73B"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}