CVE-2026-90362

Unknown

Last modified

CVE-2026-90362 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: drm/msm/dsi: Drop dev_pm_opp_set_rate(0) dev_pm_opp_set_rate(0) removes the vote specified in required-opps but does not actually park the clock, making it run without the necessary power backing. Drop the explicit call to it. Every call site of ops->link_clk_disable() is followed by pm_runtime_put(), so the power vote will be rescinded if deemed safe. Patchwork: https://patchwork.freedesktop.org/patch/742783/.

Description

In the Linux kernel, the following vulnerability has been resolved: drm/msm/dsi: Drop dev_pm_opp_set_rate(0) dev_pm_opp_set_rate(0) removes the vote specified in required-opps but does not actually park the clock, making it run without the necessary power backing. Drop the explicit call to it. Every call site of ops->link_clk_disable() is followed by pm_runtime_put(), so the power vote will be rescinded if deemed safe. Patchwork: https://patchwork.freedesktop.org/patch/742783/

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 32d3e0feccfe2d07e73aaa322766ab04b3c9d594, < bc1df05cccdb4f08aa42e736b54d265c6c11a45b; >= 32d3e0feccfe2d07e73aaa322766ab04b3c9d594, < 27e181c185194baf5c1ef18bbff1fc3bc283ef21; >= 32d3e0feccfe2d07e73aaa322766ab04b3c9d594, < 5c3e537db05021c93ea40a46bd0c50eee2f30f87; >= 32d3e0feccfe2d07e73aaa322766ab04b3c9d594, < d3e8355a63cead3dedaa52f46cd1ee9796fdc7a8; >= 32d3e0feccfe2d07e73aaa322766ab04b3c9d594, < 393b43cc12c95f3d2762a06f799807313029032e; >= 32d3e0feccfe2d07e73aaa322766ab04b3c9d594, < 83bc4eab83ae5ab88d410148a2e73e09e6f21c04; >= 32d3e0feccfe2d07e73aaa322766ab04b3c9d594, < 00008e6f544c2d480f920ab1e593a46cfb87cead; >= 32d3e0feccfe2d07e73aaa322766ab04b3c9d594, < 06b7ba206561619bb34116f49e0ef26b867ce3aa
LinuxLinux5.9

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-90362?
In the Linux kernel, the following vulnerability has been resolved: drm/msm/dsi: Drop dev_pm_opp_set_rate(0) dev_pm_opp_set_rate(0) removes the vote specified in required-opps but does not actually park the clock, making it run without the necessary power backing. Drop the explicit call to it. Every call site of ops->link_clk_disable() is followed by pm_runtime_put(), so the power vote will be rescinded if deemed safe. Patchwork: https://patchwork.freedesktop.org/patch/742783/
How severe is CVE-2026-90362?
Severity scoring for CVE-2026-90362 is pending analysis.
How do I fix CVE-2026-90362?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-90362?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST