Remote Procedure Handling Vulnerability in Linux Kernel Affecting Qualcomm Devices
CVE-2026-93272

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-93272?

A vulnerability exists within the Linux kernel's handling of power domain regulators in the remote process handling code specific to Qualcomm SDM632 devices. The issue arises when the information pointer is improperly incremented, which could lead to out-of-bounds access, particularly noticeable in kernels compiled with LLVM. This situation produces a 'regulator request with no identifier' error due to zeroed-out memory, impacting the kernel's functionality. The flaw has been addressed by avoiding the pointer increment when the number of power domains exceeds the number of available regulators, thus preventing the potential for exploitation.

Affected Version(s)

Linux 65991ea8a6d1e68effdc01d95ebe39f1653f7b71

Linux 65991ea8a6d1e68effdc01d95ebe39f1653f7b71 < 3dbc90b9c22ea96e37bf55f6011e63b5123ec668

Linux 654c295f9079d2c7875172142022168e34c4e34e

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.