PT-2026-97963 · Linux · Linux

CVE-2026-93276

·

Published

2026-09-24

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
phy: renesas: phy-rcar-gen3-usb2: Fix devm action registration for disabled VBUS regulator
devm regulator get exclusive() initialises the regulator with enable count = 1, requiring the consumer to disable it before release.
The devm disable action was previously only registered when the caller explicitly requested enable, so when the regulator was left in its initial enabled state without an explicit enable call, the cleanup path skipped decrementing enable count, triggering a WARN ON during regulator release on device removal.
Fix this by always registering the devm disable action based on the actual enabled state via regulator is enabled(), regardless of whether the caller requested an explicit enable. This covers both the explicitly enabled case and the initial state set by devm regulator get exclusive().
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-93276

Affected Products

Linux