CVE-2026-90404

Source
https://cve.org/CVERecord?id=CVE-2026-90404
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90404.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90404
Downstream
Published
2026-09-17T16:09:33Z
Modified
2026-09-18T03:48:38Z
Summary
platform/chrome: cros_ec_debugfs: Unregister panic notifier
Details

In the Linux kernel, the following vulnerability has been resolved:

platform/chrome: cros_ec_debugfs: Unregister panic notifier

cros_ec_debugfs_probe() registers notifier_panic with the EC panic notifier chain. The remove path tears down debugfs and the console log, but leaves the notifier registered. A later panic notification can call back into the removed instance and queue work that accesses released data.

Unregister the panic notifier before tearing down the debugfs and console log state.

This issue was found by a static analysis tool.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90404.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
d90fa2c64d59f5f151beeef5dbc599784b3391ca
Fixed
56989e2a9c292ff7689603feed41d030301ca636
Fixed
a5d3128b06ccfc398c2e456fddebadce52310bd8
Fixed
e2cbe14361d7cb0b5abd66d87f3afa0e16efde9f
Fixed
05c1081ae4503e45b934b390350f942db3208892
Fixed
e5954d3031fb55dd31aa59bae477d63c68e941c0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90404.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.3.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90404.json"