« Volver al listado

CVE-2026-90147

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

clk: devres: fix cleanup in devm_clk_get_optional_enabled_with_rate()

devm_clk_get_optional_enabled_with_rate() registers its cleanup action before setting the clock rate. If setting the rate fails, it attempts to disable and unprepare a clock that was never enabled. This issue was spotted while reviewing "rust: clk: add devres-managed clks" [1].

Register the cleanup action only after successfully preparing and enabling the clock.

[1]: https://lore.kernel.org/rust-for-linux/20260706-clk-type-state-v5-3-67c5f326a16c@collabora.com

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90147",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "9934a1bd45b2b03f6d1204a6ae2780d3b009799f",
              "lessThan": "9a365f41fe0f227ef5a269e240233bd0bffc66c9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9934a1bd45b2b03f6d1204a6ae2780d3b009799f",
              "lessThan": "9d4843f1051259854f724e9cdc5b9eac56327037",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9934a1bd45b2b03f6d1204a6ae2780d3b009799f",
              "lessThan": "647157fecb42b72d930e7b7d0bfbc5f2db9a858a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9934a1bd45b2b03f6d1204a6ae2780d3b009799f",
              "lessThan": "0d4d262c1664365e17e0a5ba2ab79f4db484b44e",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/clk/clk-devres.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.12"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.12",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/clk/clk-devres.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:07.603",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0d4d262c1664365e17e0a5ba2ab79f4db484b44e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/647157fecb42b72d930e7b7d0bfbc5f2db9a858a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9a365f41fe0f227ef5a269e240233bd0bffc66c9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9d4843f1051259854f724e9cdc5b9eac56327037",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nclk: devres: fix cleanup in devm_clk_get_optional_enabled_with_rate()\n\ndevm_clk_get_optional_enabled_with_rate() registers its cleanup action\nbefore setting the clock rate. If setting the rate fails, it attempts to\ndisable and unprepare a clock that was never enabled. This issue was\nspotted while reviewing \"rust: clk: add devres-managed clks\" [1].\n\nRegister the cleanup action only after successfully preparing and enabling\nthe clock.\n\n[1]: https://lore.kernel.org/rust-for-linux/20260706-clk-type-state-v5-3-67c5f326a16c@collabora.com"
    }
  ],
  "lastModified": "2026-09-17T17:17:07.603",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}