CVE-2026-90362

high

Description

In the Linux kernel, the following vulnerability has been resolved: drm/msm/dsi: Drop dev_pm_opp_set_rate(0) dev_pm_opp_set_rate(0) removes the vote specified in required-opps but does not actually park the clock, making it run without the necessary power backing. Drop the explicit call to it. Every call site of ops->link_clk_disable() is followed by pm_runtime_put(), so the power vote will be rescinded if deemed safe. Patchwork: https://patchwork.freedesktop.org/patch/742783/

References

https://git.kernel.org/stable/c/d3e8355a63cead3dedaa52f46cd1ee9796fdc7a8

https://git.kernel.org/stable/c/bc1df05cccdb4f08aa42e736b54d265c6c11a45b

https://git.kernel.org/stable/c/83bc4eab83ae5ab88d410148a2e73e09e6f21c04

https://git.kernel.org/stable/c/5c3e537db05021c93ea40a46bd0c50eee2f30f87

https://git.kernel.org/stable/c/393b43cc12c95f3d2762a06f799807313029032e

https://git.kernel.org/stable/c/27e181c185194baf5c1ef18bbff1fc3bc283ef21

https://git.kernel.org/stable/c/06b7ba206561619bb34116f49e0ef26b867ce3aa

https://git.kernel.org/stable/c/00008e6f544c2d480f920ab1e593a46cfb87cead

Details

Source: Mitre, NVD

Published: 2026-09-17

Updated: 2026-09-17

Risk Information

CVSS v2

Base Score: 6.1

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:P/A:C

Severity: Medium

CVSS v3

Base Score: 7.1

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Severity: High

EPSS

EPSS: 0.0021