Junglewise Threat Intelligence

CVE-2026-90147: Linux kernel clock cleanup resource leak in devm_clk_get_optional_enabled_with_rate

CVE-2026-90147 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A flaw in the Linux kernel's clock device resource management function can cause improper cleanup if clock rate configuration fails, potentially leaving unprepared clocks in an invalid state. This is a logic error in error-handling code that could lead to kernel instability or undefined behavior when clock initialization encounters errors.

Technical details

The vulnerability is a resource cleanup ordering bug in the devm_clk_get_optional_enabled_with_rate() function in drivers/clk/clk-devres.c. The function registered its cleanup action (to disable and unprepare the clock) before attempting to set the clock rate. If the clock rate setting failed, the cleanup handler would attempt to disable and unprepare a clock that was never successfully enabled, resulting in incorrect state management. The fix moves the devm_add_action_or_reset() call to occur only after both clk_prepare_enable() and clk_set_rate() succeed, ensuring cleanup is only registered for clocks that were actually enabled. No authentication or network access is required—this affects any kernel code path using the vulnerable function. The flaw could cause kernel warnings, oops, or undefined behavior in error scenarios.

Affected products

  • Linux Linux kernel 5.9 and later (introduced in commit 9934a1bd45b2)

Timeline

  • 2026-09-17: disclosed
  • 2026-08-17: patched: Upstream fix applied to mainline

References

Related threats