CVE-2026-90147

high

Description

In the Linux kernel, the following vulnerability has been resolved: clk: devres: fix cleanup in devm_clk_get_optional_enabled_with_rate() devm_clk_get_optional_enabled_with_rate() registers its cleanup action before setting the clock rate. If setting the rate fails, it attempts to disable and unprepare a clock that was never enabled. This issue was spotted while reviewing "rust: clk: add devres-managed clks" [1]. Register the cleanup action only after successfully preparing and enabling the clock. [1]: https://lore.kernel.org/rust-for-linux/[email protected]

References

https://git.kernel.org/stable/c/9d4843f1051259854f724e9cdc5b9eac56327037

https://git.kernel.org/stable/c/9a365f41fe0f227ef5a269e240233bd0bffc66c9

https://git.kernel.org/stable/c/647157fecb42b72d930e7b7d0bfbc5f2db9a858a

https://git.kernel.org/stable/c/0d4d262c1664365e17e0a5ba2ab79f4db484b44e

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-81740

Details

Source: Mitre, NVD

Published: 2026-09-17

Updated: 2026-09-17

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 8.4

Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.00209