« Volver al listado

CVE-2026-90422

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

clk: mediatek: pllfh: Fix IO remapping leak in register_pllfhs error path

When mtk_clk_register_pllfhs function fails to register a PLL, it unregisters all PLLs and cleans up itself in its error path before returning, so the function callers don't need to do it.

But contrary to mtk_clk_unregister_pllfhs function, that does almost the same sequence, it does not free the IO memory mapped on fhctl node, leading to a leak.

Fix this leak by factorizing the cleanup sequence in a new private function and use it both mtk_clk_register_pllfhs and mtk_clk_unregister_pllfhs functions.

Leer descripción completaMostrar menos

Also, change the loop index start value to avoid the -1 operation on index at each loop.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90422",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "d7964de8a8ea800910fdd4e365c42a9e7d5c54aa",
              "lessThan": "d35e45e5bad4fabcf122126402b6c6dcb4379672",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "d7964de8a8ea800910fdd4e365c42a9e7d5c54aa",
              "lessThan": "fea0b4fd891a2af77b55e05b950e7ea55b5d234e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "d7964de8a8ea800910fdd4e365c42a9e7d5c54aa",
              "lessThan": "540d91480bcb1b28a62d7023aa70947ea44c55b9",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/clk/mediatek/clk-pllfh.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.2"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.2",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/clk/mediatek/clk-pllfh.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:46.770",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/540d91480bcb1b28a62d7023aa70947ea44c55b9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d35e45e5bad4fabcf122126402b6c6dcb4379672",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fea0b4fd891a2af77b55e05b950e7ea55b5d234e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nclk: mediatek: pllfh: Fix IO remapping leak in register_pllfhs error path\n\nWhen mtk_clk_register_pllfhs function fails to register a PLL, it\nunregisters all PLLs and cleans up itself in its error path before\nreturning, so the function callers don't need to do it.\n\nBut contrary to mtk_clk_unregister_pllfhs function, that does almost\nthe same sequence, it does not free the IO memory mapped on fhctl node,\nleading to a leak.\n\nFix this leak by factorizing the cleanup sequence in a new private\nfunction and use it both mtk_clk_register_pllfhs and\nmtk_clk_unregister_pllfhs functions.\n\nAlso, change the loop index start value to avoid the -1 operation on\nindex at each loop."
    }
  ],
  "lastModified": "2026-09-17T17:17:46.770",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}