CVE-2026-90402

Source
https://cve.org/CVERecord?id=CVE-2026-90402
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90402.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90402
Downstream
Published
2026-09-17T16:09:32Z
Modified
2026-09-18T03:48:38Z
Summary
bus: mhi: host: Fix controller cleanup on EDL sysfs failure
Details

In the Linux kernel, the following vulnerability has been resolved:

bus: mhi: host: Fix controller cleanup on EDL sysfs failure

mhi_register_controller() adds the controller device before creating the optional trigger_edl sysfs file. If sysfs_create_file() fails, the error path only drops the device reference and leaves the device registered.

Hence, call device_del() in the error path before put_device().

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90402.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
17553ba8e19dee8770b3dcc597d49dcc3418f3b0
Fixed
7943dc67250fad6ceac0dd089c6ad5776e4be71d
Fixed
4fb17a7c437f145353e93e6a9791f6db70e1cc63
Fixed
4743959aa8d876b5b456a62e8a62eb770db7afe9
Fixed
0d5b9e66591d4e2a4376ac82c8cda889a29ba3ee

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90402.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.10.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90402.json"