CVE-2026-90026

Source
https://cve.org/CVERecord?id=CVE-2026-90026
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90026.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90026
Downstream
Published
2026-09-16T10:33:29Z
Modified
2026-09-18T03:48:35Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
usb: typec: qcom-pmic: cancel reset_work on stop
Details

In the Linux kernel, the following vulnerability has been resolved:

usb: typec: qcom-pmic: cancel reset_work on stop

pdphy_stop() disables IRQs but leaves reset_work pending. If the IRQ handler schedules it just before disable_irq(), the work runs after remove() frees the struct via devm.

Call cancel_work_sync() after disabling IRQs to close the window.

This issue was found by an in-house static analysis tool.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90026.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
a4422ff221429c600c3dc5d0394fb3738b89d040
Fixed
0b69b166852dbf1f9532b22bd49f502e5970eb95
Fixed
b9a7eed472edbfa8dec0fdeafd5e796550a8a8b7
Fixed
d4e00a1eb39174e25ef759b8fb1111bba8e87b1e
Fixed
52d556f08547733948cc40b8b11e6b68dccee7b2
Fixed
7b0df6efd143f8085bdb68778a013a46f1349913

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90026.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.5.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.51
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90026.json"