Junglewise Threat Intelligence

CVE-2026-93145: Linux kernel Qualcomm GDSC resource cleanup race condition

CVE-2026-93145 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's Qualcomm clock driver (GDSC subsystem) has a resource cleanup issue where power domain structures are not properly torn down during module unload or overlay teardown. This leaves dangling entries that prevent the driver from reinitializing correctly, causing boot failures or module reload issues on affected Qualcomm-based systems.

Technical details

The vulnerability is a resource leak and initialization logic flaw in the gdsc_unregister() function within drivers/clk/qcom/gdsc.c. The function failed to call pm_genpd_remove() on individual generic_pm_domain structures, leaving dangling entries on the global gpd_list. Upon provider unbind/rebind cycles (module unload/reload, deferred-probe replay, or OF-overlay teardown), subsequent gdsc_init() calls attempt to re-register domain names still present in the list, causing pm_genpd_init() to return -EEXIST. Additionally, there was a race condition where OF provider removal was not ordered first, potentially allowing fresh of_genpd_get_from_provider() calls to attach to domains mid-removal. The fix iterates the scs[] array and explicitly calls pm_genpd_remove() on each registered domain after subdomain links are torn down, and reorders cleanup to remove the OF provider entry first.

Affected products

  • Linux Linux kernel Qualcomm GDSC clock driver (affects multiple kernel versions)

Timeline

  • 2026-09-17: disclosed
  • 2026-06-02: patched: Fix committed upstream; backported to stable branches

References

Related threats