CVE-2026-90147

Source
https://cve.org/CVERecord?id=CVE-2026-90147
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90147.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90147
Downstream
Published
2026-09-17T16:06:42Z
Modified
2026-09-19T03:47:24Z
Summary
clk: devres: fix cleanup in devm_clk_get_optional_enabled_with_rate()
Details

In the Linux kernel, the following vulnerability has been resolved:

clk: devres: fix cleanup in devm_clk_get_optional_enabled_with_rate()

devm_clk_get_optional_enabled_with_rate() registers its cleanup action before setting the clock rate. If setting the rate fails, it attempts to disable and unprepare a clock that was never enabled. This issue was spotted while reviewing "rust: clk: add devres-managed clks" 1.

Register the cleanup action only after successfully preparing and enabling the clock.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90147.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
9934a1bd45b2b03f6d1204a6ae2780d3b009799f
Fixed
9a365f41fe0f227ef5a269e240233bd0bffc66c9
Fixed
9d4843f1051259854f724e9cdc5b9eac56327037
Fixed
647157fecb42b72d930e7b7d0bfbc5f2db9a858a
Fixed
0d4d262c1664365e17e0a5ba2ab79f4db484b44e

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90147.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.12.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90147.json"