Regulator State Management Flaw in Linux Kernel Affects USB Type-C Implementation
CVE-2026-90028
Currently unrated
What is CVE-2026-90028?
A vulnerability in the Linux kernel's implementation of USB Type-C can lead to improper handling of VBUS power state, resulting in potential warnings about unbalanced regulator disables. The flaw occurs when the aggregate regulator state is reported instead of the actual enable reference held by the consumer. If another consumer enables VBUS first, the driver might skip its own regulator enable call and attempt to drop a reference it never acquired. This poorly managed state may lead to system instability as operations could be retried based on an incorrect understanding of the current state.
Affected Version(s)
Linux b3f9d6e491fda73c319547881b78cdd2a222b293
Linux b3f9d6e491fda73c319547881b78cdd2a222b293
Linux 7.0