CVE-2026-90144
In the Linux kernel, the following vulnerability has been resolved:
dpll: fix NULL deref in dpll_device_ops() during teardown race
When the last owner of a dpll device unregisters while a foreign driver still holds a pin on it via dpll_pin_on_pin_register(), the dpll object stays alive with an empty registration list. A pin notification queued before the unregister (e.g. ice reacting to zl3073x_i2c removal) then walks pin->dpll_refs into dpll_device_ops(), which trips the WARN_ON and dereferences the missing registration. dpll_lock cannot help because the notification work was queued before the unregistering driver took the lock.
Leer descripción completaMostrar menos
Treat the empty registration list as a legitimate transient state. Make dpll_priv() and dpll_device_ops() return NULL in that case and make every pin netlink path that resolves a device from a pin skip such dplls. dpll_cmd_pin_get_one() picks a ref with a live registration and returns -ENODEV when there is none, the pin dumpit skips such a pin instead of aborting the dump, dpll_msg_add_pin_dplls() and the frequency, esync, reference sync and phase adjust set paths skip dead refs, and dpll_pin_parent_device_set() validates the parent with dpll_device_get_by_id(). dpll_pin_register() is the last caller that dereferenced the device ops without a check, so move its frequency monitor validation under dpll_lock and tolerate a missing registration there as well.
The empty registration list is equivalent to a cleared DPLL_REGISTERED mark, both transitions happen under dpll_lock in dpll_device_register() and dpll_device_unregister(). A pin notification for a pin whose dplls are all gone is now dropped with -ENODEV instead of crashing, all callers in the core ignore that return value.
Detalles técnicos trazas, registros y código del informe original
WARNING: drivers/dpll/dpll_core.c:1092 at dpll_device_ops+0x24/0x40, CPU#83: kworker/u576:3/23471 Modules linked in: ... ice ... zl3073x_i2c(-) ... zl3073x ... Workqueue: ice_dpll_wq ice_dpll_pin_notify_work [ice] RIP: 0010:dpll_device_ops+0x24/0x40 Call Trace: <TASK> dpll_cmd_pin_get_one+0x336/0x520 dpll_pin_event_send+0x82/0x140 dpll_pin_on_pin_unregister+0xbb/0x160 ice_dpll_pin_notify_work+0x1bc/0x1f0 [ice] process_one_work+0x19e/0x370 worker_thread+0x1a6/0x310 kthread+0xe4/0x120 ret_from_fork+0x1a1/0x270 ret_from_fork_asm+0x1a/0x30 </TASK> ---[ end trace 0000000000000000 ]--- BUG: kernel NULL pointer dereference, address: 0000000000000010 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.20%
- Percentil entre todas las CVEs puntuadas: 9
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-90144",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "9431063ad323ac864750aeba4d304389bc42ca4e",
"lessThan": "fdbf04e3e01a872d0ef2149f846f1a3e3cb54f5b",
"versionType": "git"
},
{
"status": "affected",
"version": "9431063ad323ac864750aeba4d304389bc42ca4e",
"lessThan": "33f016b23a219fe034213849b51436b8e79df251",
"versionType": "git"
}
],
"programFiles": [
"drivers/dpll/dpll_core.c",
"drivers/dpll/dpll_netlink.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.7"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.7",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "7.2.6",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/dpll/dpll_core.c",
"drivers/dpll/dpll_netlink.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-17T17:17:07.233",
"references": [
{
"url": "https://git.kernel.org/stable/c/33f016b23a219fe034213849b51436b8e79df251",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/fdbf04e3e01a872d0ef2149f846f1a3e3cb54f5b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndpll: fix NULL deref in dpll_device_ops() during teardown race\n\nWhen the last owner of a dpll device unregisters while a foreign driver\nstill holds a pin on it via dpll_pin_on_pin_register(), the dpll object\nstays alive with an empty registration list. A pin notification queued\nbefore the unregister (e.g. ice reacting to zl3073x_i2c removal) then\nwalks pin->dpll_refs into dpll_device_ops(), which trips the WARN_ON and\ndereferences the missing registration. dpll_lock cannot help because the\nnotification work was queued before the unregistering driver took the\nlock.\n\nTreat the empty registration list as a legitimate transient state. Make\ndpll_priv() and dpll_device_ops() return NULL in that case and make\nevery pin netlink path that resolves a device from a pin skip such\ndplls. dpll_cmd_pin_get_one() picks a ref with a live registration and\nreturns -ENODEV when there is none, the pin dumpit skips such a pin\ninstead of aborting the dump, dpll_msg_add_pin_dplls() and the\nfrequency, esync, reference sync and phase adjust set paths skip dead\nrefs, and dpll_pin_parent_device_set() validates the parent with\ndpll_device_get_by_id(). dpll_pin_register() is the last caller that\ndereferenced the device ops without a check, so move its frequency\nmonitor validation under dpll_lock and tolerate a missing registration\nthere as well.\n\nThe empty registration list is equivalent to a cleared DPLL_REGISTERED\nmark, both transitions happen under dpll_lock in dpll_device_register()\nand dpll_device_unregister(). A pin notification for a pin whose dplls\nare all gone is now dropped with -ENODEV instead of crashing, all\ncallers in the core ignore that return value.\n\n WARNING: drivers/dpll/dpll_core.c:1092 at dpll_device_ops+0x24/0x40,\n CPU#83: kworker/u576:3/23471\n Modules linked in: ... ice ... zl3073x_i2c(-) ... zl3073x ...\n Workqueue: ice_dpll_wq ice_dpll_pin_notify_work [ice]\n RIP: 0010:dpll_device_ops+0x24/0x40\n Call Trace:\n <TASK>\n dpll_cmd_pin_get_one+0x336/0x520\n dpll_pin_event_send+0x82/0x140\n dpll_pin_on_pin_unregister+0xbb/0x160\n ice_dpll_pin_notify_work+0x1bc/0x1f0 [ice]\n process_one_work+0x19e/0x370\n worker_thread+0x1a6/0x310\n kthread+0xe4/0x120\n ret_from_fork+0x1a1/0x270\n ret_from_fork_asm+0x1a/0x30\n </TASK>\n ---[ end trace 0000000000000000 ]---\n BUG: kernel NULL pointer dereference, address: 0000000000000010\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page"
}
],
"lastModified": "2026-09-17T17:17:07.233",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}