CVE-2026-90122
Last modified
CVE-2026-90122 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: clk: visconti: Make sure clk_init_data is fully initialized The clk_init_data structure contains several mutually-exclusive members for different methods to specify the possible parents of a clock, prompting drivers to initialize only the members they need. However, not initializing all members may cause subtle issues, which are only exposed when CONFIG_INIT_STACK_ALL_PATTERN or CONFIG_INIT_STACK_NONE is enabled. visconti_clk_register_gate() fills in init.parent_data, and assumes that init.parent_names is NULL.
Description
In the Linux kernel, the following vulnerability has been resolved: clk: visconti: Make sure clk_init_data is fully initialized The clk_init_data structure contains several mutually-exclusive members for different methods to specify the possible parents of a clock, prompting drivers to initialize only the members they need. However, not initializing all members may cause subtle issues, which are only exposed when CONFIG_INIT_STACK_ALL_PATTERN or CONFIG_INIT_STACK_NONE is enabled. visconti_clk_register_gate() fills in init.parent_data, and assumes that init.parent_names is NULL. However, the latter in uninitialized, and thus may cause a crash. Make sure all members are fully initialized, to fix such bugs, and to avoid future breakage when converting drivers to a different method for specifying the parents.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= b4cbe606dc3674b25cb661e7cd1a1c6ddaaafaaa, < 0e97c22b286e1918c6f48bad7e77fb8240a24b4a; >= b4cbe606dc3674b25cb661e7cd1a1c6ddaaafaaa, < 9f756f1965bad65e6066608f33c36988cd10302a; >= b4cbe606dc3674b25cb661e7cd1a1c6ddaaafaaa, < 1cc0539e5b0906bace15d3fc7347b344a017cc02; >= b4cbe606dc3674b25cb661e7cd1a1c6ddaaafaaa, < 8f7980033e9f7ecaaecd873a0b5bf6b6c87d7e5a; >= b4cbe606dc3674b25cb661e7cd1a1c6ddaaafaaa, < 5ecfa72e74c6e2a765fa5bc1da574e5beae588f2; >= b4cbe606dc3674b25cb661e7cd1a1c6ddaaafaaa, < 39c0e6c844a14945040cca4ccf6997792ab764c4 |
| Linux | Linux | 5.17 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-90122?
How severe is CVE-2026-90122?
How do I fix CVE-2026-90122?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-90117In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90118In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-90119In the Linux kernel, the following vulnerability has been re…
- CVE-2026-9012Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-90120In the Linux kernel, the following vulnerability has been re…8.4
- CVE-2026-90121In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90123In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90124In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90125In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90126In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90127In the Linux kernel, the following vulnerability has been re…
- CVE-2026-90128In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-90122?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
