CVE-2026-90122

Source
https://cve.org/CVERecord?id=CVE-2026-90122
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90122.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90122
Downstream
Published
2026-09-17T16:06:25Z
Modified
2026-09-19T03:47:28Z
Summary
clk: visconti: Make sure clk_init_data is fully initialized
Details

In the Linux kernel, the following vulnerability has been resolved:

clk: visconti: Make sure clk_init_data is fully initialized

The clk_init_data structure contains several mutually-exclusive members for different methods to specify the possible parents of a clock, prompting drivers to initialize only the members they need. However, not initializing all members may cause subtle issues, which are only exposed when CONFIG_INIT_STACK_ALL_PATTERN or CONFIG_INIT_STACK_NONE is enabled.

visconti_clk_register_gate() fills in init.parent_data, and assumes that init.parent_names is NULL. However, the latter in uninitialized, and thus may cause a crash.

Make sure all members are fully initialized, to fix such bugs, and to avoid future breakage when converting drivers to a different method for specifying the parents.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90122.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b4cbe606dc3674b25cb661e7cd1a1c6ddaaafaaa
Fixed
0e97c22b286e1918c6f48bad7e77fb8240a24b4a
Fixed
9f756f1965bad65e6066608f33c36988cd10302a
Fixed
1cc0539e5b0906bace15d3fc7347b344a017cc02
Fixed
8f7980033e9f7ecaaecd873a0b5bf6b6c87d7e5a
Fixed
5ecfa72e74c6e2a765fa5bc1da574e5beae588f2
Fixed
39c0e6c844a14945040cca4ccf6997792ab764c4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90122.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.17.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90122.json"