Junglewise Threat Intelligence

CVE-2026-90360: Linux kernel regulator subsystem race condition during system suspend

CVE-2026-90360 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's power regulator management subsystem has a race condition where initialization cleanup work can run concurrently with system suspend, causing I2C communication failures. This can result in kernel warnings and potential system instability during suspend/resume cycles, though it does not provide an attack vector for privilege escalation or data compromise.

Technical details

The vulnerability is a race condition in the regulator core subsystem where regulator_init_complete_work is scheduled using schedule_delayed_work() with system_wq (a non-freezable workqueue). Approximately 30 seconds after boot, this work disables unused regulators via I2C transfers. If this work executes concurrently with system suspend (when the I2C adapter is already suspended), __i2c_transfer() returns -ESHUTDOWN, triggering kernel warnings. The fix switches to system_freezable_wq so the work is frozen before device suspension, eliminating the race. This is a scheduling/synchronization defect rather than a security vulnerability; no authentication bypass, privilege escalation, or data exposure is possible.

Affected products

  • Linux Linux kernel Approximately 2.6.11 through 6.x and later (based on stable tree branches); original issue introduced by commit 55576cf18537

Timeline

  • 2026-09-17: disclosed

References

Related threats