Regulator State Management Flaw in Linux Kernel Affects USB Type-C Implementation
CVE-2026-90028

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-90028?

A vulnerability in the Linux kernel's implementation of USB Type-C can lead to improper handling of VBUS power state, resulting in potential warnings about unbalanced regulator disables. The flaw occurs when the aggregate regulator state is reported instead of the actual enable reference held by the consumer. If another consumer enables VBUS first, the driver might skip its own regulator enable call and attempt to drop a reference it never acquired. This poorly managed state may lead to system instability as operations could be retried based on an incorrect understanding of the current state.

Affected Version(s)

Linux b3f9d6e491fda73c319547881b78cdd2a222b293

Linux b3f9d6e491fda73c319547881b78cdd2a222b293

Linux 7.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.