Impact
The flaw lies in the hd3ss3220 driver for USB‑C control in the Linux kernel. When a consumer checks whether VBUS is enabled using regulator_is_enabled(), the function returns an aggregate regulator state that does not distinguish whether the specific consumer holds an enable reference. If another consumer enables VBUS before this one, the hd3ss3220 driver may skip its own regulator_enable() call. Later, when it calls regulator_disable(), it attempts to drop a reference that was never acquired, triggering an unbalanced regulator disable warning in the kernel. This incorrect reference counting is a pure resource‑management bug; it does not provide direct privilege escalation or data disclosure. However, the warning can indicate that the kernel’s regulator subsystem is in an inconsistent state, potentially leading to instability if the mis‑balancing persists.
Affected Systems
The flaw affects the Linux kernel itself. Vendor marks only list “Linux:Linux”, and specific version information is not supplied. Any kernel release that includes the hd3ss3220 driver before the patch is vulnerable, regardless of distribution.
Risk and Exploitability
The exploitation probability is low, with an EPSS score of < 1% and no listed public exploits. The issue is not in the CISA KEV catalog, and no CVSS score is provided. Based on the description, the likely attack vector is a physical or local user who repeatedly interacts with a USB‑C device powered via the hd3ss3220 regulator—such as frequent plugging and unplugging of peripherals—although casual use is unlikely to trigger catastrophic failure.
OpenCVE Enrichment