Description
In the Linux kernel, the following vulnerability has been resolved:

phy: rockchip-samsung-dcphy: fix out-of-range max_register

The PHY register block is 64KB, so with a register stride of 4 the
last accessible register sits at offset 0xfffc. max_register names
0x10000, one register past the end of the mapping: dumping the
registers through the regmap debugfs interface reads beyond the
ioremapped region and oopses on the unmapped page. The oops fires
with the regmap lock held, so later PHY operations deadlock.
Published: 2026-09-11
Score: 4.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

A kernel driver for Rockchip‑Samsung integrated circuits contains a module that incorrectly sets the maximum register offset to 0x10000, one entry beyond the 64 KB register block that is mapped with a 4‑byte stride. When the regmap debugfs interface dumps the register block, the driver tries to read this out‑of‑range address. The read causes a page fault on an unmapped page, provoking a kernel oops. Because the regmap lock remains held, subsequent PHY operations deadlock. This out‑of‑bounds read (CWE‑125) leads to a denial‑of‑service by crashing the kernel and halting further driver activity.

Affected Systems

All Linux kernel builds that contain the unpatched rockchip‑samsung‑dcphy driver are affected. This driver is present in kernel releases before the commit that introduced the fix. Systems that use Rockchip or Samsung integrated hardware and are running a kernel version that does not include the patch are potentially vulnerable. Distribution kernels that have not yet incorporated the upstream change are also at risk.

Risk and Exploitability

The CVSS score of 4.1 indicates medium severity, while the EPSS score is less than 1%, implying a very low probability of exploitation. The vulnerability is not listed in CISA KEV, meaning no widespread exploitation has been reported. The likely attack vector is a local privileged user who can access the regmap debugfs interface; the attacker would trigger an out‑of‑bounds read that causes a kernel oops, holding the regmap lock and leading to a deadlock and subsequent denial of service on the affected system.

Generated by OpenCVE AI on September 15, 2026 at 19:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the rockchip‑samsung‑dcphy driver patch that fixes the out‑of‑range register index.
  • If an upgrade is not possible, restrict access to the regmap debugfs interface by unmounting debugfs or adjusting permissions on the driver’s debugfs entries to prevent a vulnerable read from being executed.
  • If the driver is not required, disable the rockchip‑samsung‑dcphy module in the kernel configuration to eliminate this vulnerability.

Generated by OpenCVE AI on September 15, 2026 at 19:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: phy: rockchip-samsung-dcphy: fix out-of-range max_register The PHY register block is 64KB, so with a register stride of 4 the last accessible register sits at offset 0xfffc. max_register names 0x10000, one register past the end of the mapping: dumping the registers through the regmap debugfs interface reads beyond the ioremapped region and oopses on the unmapped page. The oops fires with the regmap lock held, so later PHY operations deadlock.
Title phy: rockchip-samsung-dcphy: fix out-of-range max_register
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:46:33.680Z

Reserved: 2026-09-11T19:38:34.752Z

Link: CVE-2026-89721

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:20:01.090

Modified: 2026-09-11T20:20:01.090

Link: CVE-2026-89721

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:46:33Z

Links: CVE-2026-89721 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:30:12Z

Weaknesses