CVE-2026-90147

Summary

In the Linux kernel, the following vulnerability has been resolved:

clk: devres: fix cleanup in devm_clk_get_optional_enabled_with_rate()

devm_clk_get_optional_enabled_with_rate() registers its cleanup action before setting the clock rate. If setting the rate fails, it attempts to disable and unprepare a clock that was never enabled. This issue was spotted while reviewing "rust: clk: add devres-managed clks" 1.

Register the cleanup action only after successfully preparing and enabling the clock.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux9934a1bd45b2b03f6d1204a6ae2780d3b009799f < 9a365f41fe0f227ef5a269e240233bd0bffc66c9affected
LinuxLinux9934a1bd45b2b03f6d1204a6ae2780d3b009799f < 9d4843f1051259854f724e9cdc5b9eac56327037affected
LinuxLinux9934a1bd45b2b03f6d1204a6ae2780d3b009799f < 647157fecb42b72d930e7b7d0bfbc5f2db9a858aaffected
LinuxLinux9934a1bd45b2b03f6d1204a6ae2780d3b009799f < 0d4d262c1664365e17e0a5ba2ab79f4db484b44eaffected
LinuxLinux6.12affected
LinuxLinux0 < 6.12unaffected
LinuxLinux6.12.110 <= 6.12.*unaffected
LinuxLinux6.18.52 <= 6.18.*unaffected
LinuxLinux7.2.6 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References