CVE-2026-93273

Source
https://cve.org/CVERecord?id=CVE-2026-93273
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93273.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93273
Downstream
Published
2026-09-24T15:52:15Z
Modified
2026-09-25T03:48:54Z
Summary
regulator: tps6594: Fix device node reference leaks in multiphase loop
Details

In the Linux kernel, the following vulnerability has been resolved:

regulator: tps6594: Fix device node reference leaks in multiphase loop

In tps6594_regulator_probe(), the multi-phase configuration loop calls of_find_node_by_name() to find buck nodes by name, and of_get_parent() twice to navigate to the PMIC parent node. None of the acquired node references (np, intermediate parent, np_pmic_parent) are ever released via of_node_put(), causing a reference leak on every loop iteration.

Additionally, of_find_node_by_name() can return NULL, but the result was immediately passed to of_node_full_name() and of_get_parent() without a NULL check, which could lead to a NULL pointer dereference.

Fix this by:

  • Adding a NULL check for np after of_find_node_by_name()
  • Storing the intermediate parent node in a local variable np_parent
  • Calling of_node_put() on np, np_parent and np_pmic_parent at the end of each loop iteration
Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93273.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
f17ccc5deb4d024bb52fd3433471e77ab7ae9ad8
Fixed
28f70e0aa767a8f022c70ed75ecef227dc668121
Fixed
4a672bff99f6b58dde419fd12b3a53da137f032d
Fixed
68ce4f8223b78f8616ec7f4a02c38988eae627d2
Fixed
fceac25487b21d6db940d2aed368e465d89cd1f4
Fixed
7fd28093b3effc4f92566466df364622830ec608

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93273.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.5.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93273.json"