Junglewise Threat Intelligence

CVE-2026-93113: Linux kernel clk-qcom camcc-sc8280xp GDSC clock handling issue

CVE-2026-93113 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's camera clock controller driver for Qualcomm SC8280XP processors produces a runtime warning when power domains are disabled during sync_state operations. This occurs when the system attempts to shut down unused camera clocks, but the GDSC (Generic Dynamic Supply Controller) logic power domain fails to transition cleanly to the expected state, causing potential instability in camera subsystem initialization.

Technical details

The vulnerability is a GDSC power domain state management issue in the clk/qcom/camcc-sc8280xp driver that triggers during the clock framework's sync_state synchronization with the power domain subsystem. The root cause is that CAMCC_GDSC_CLK is registered as a gated clock, and when sync_state support was introduced, the shutdown of unused clocks causes the GDSC toggle logic to fail with a "status stuck at 'on'" warning in gdsc_toggle_logic(). The issue is triggered automatically during kernel initialization on systems with this SoC, is non-exploitable, and is resolved by unregistering the problematic GDSC clock from the clock provider. The fix involves removing the CAMCC_GDSC_CLK entry from the clock registration list.

Affected products

  • Linux Linux kernel 7.1.0 and later

Timeline

  • 2026-09-17: disclosed

Related threats