Description
In the Linux kernel, the following vulnerability has been resolved:

iio: dac: m62332: Fix regulator reference count imbalance

m62332_set_value() enables the Vcc regulator on every write of a
non-zero value and disables it on every write of zero, without tracking
the channel's current state. Because the regulator is reference counted,
changing a channel directly from one non-zero value to another enables
it more than once, while a later write of zero disables it only once.
The reference count never returns to zero and the regulator is left
enabled indefinitely.

Only enable the regulator on the transition from zero to non-zero, and
only disable it on the transition from non-zero to zero, using the
previously stored channel value to detect the edge. Balance the
regulator on the I2C error path so the reference count stays consistent
if the write fails.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

In the Linux kernel’s Industrial I/O subsystem, the m62332 digital‑to‑analog converter driver contains a logic error that mishandles the Vcc regulator’s reference counter. Each time a non‑zero value is written, the regulator is enabled again without checking its current state, and a zero write disables it only once. On repeated non‑zero writes the reference count can exceed one, while a subsequent zero write decrements it only once, leaving the count never zero. The regulator therefore stays powered indefinitely, consuming power and potentially causing hardware wear or failure. Such uncontrolled power consumption can lead to a denial of service or premature battery depletion in portable devices.

Affected Systems

Any Linux kernel installation that includes the m62332 driver is affected, regardless of version. The advisory lists the kernel as the impacted vendor and does not provide a specific version range, so all builds that compile the m62332 driver without the referenced patch are vulnerable.

Risk and Exploitability

Exploitation requires write access to the device node associated with the m62332 DAC, which typically demands local or privileged privileges. The EPSS score is reported as less than 1 %, indicating a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, systems that rely on precise regulator control—especially battery‑powered or safety‑critical devices—face significant risk from indefinite regulator activation.

Generated by OpenCVE AI on September 18, 2026 at 08:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a release that contains the regulator reference‑count patch (see the advisory commits).
  • If a kernel upgrade cannot be performed immediately, prevent use of the m62332 DAC by removing its device tree entry or disabling the driver module until the patch is applied.
  • Disable the regulator via sysfs by setting the appropriate attribute, preventing writes that could trigger the imbalance until the kernel patch is applied.

Generated by OpenCVE AI on September 18, 2026 at 08:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: iio: dac: m62332: Fix regulator reference count imbalance m62332_set_value() enables the Vcc regulator on every write of a non-zero value and disables it on every write of zero, without tracking the channel's current state. Because the regulator is reference counted, changing a channel directly from one non-zero value to another enables it more than once, while a later write of zero disables it only once. The reference count never returns to zero and the regulator is left enabled indefinitely. Only enable the regulator on the transition from zero to non-zero, and only disable it on the transition from non-zero to zero, using the previously stored channel value to detect the edge. Balance the regulator on the I2C error path so the reference count stays consistent if the write fails.
Title iio: dac: m62332: Fix regulator reference count imbalance
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:32:25.608Z

Reserved: 2026-09-11T19:38:34.776Z

Link: CVE-2026-89936

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:03.027

Modified: 2026-09-16T11:17:03.027

Link: CVE-2026-89936

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:45:07Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption