Description
In the Linux kernel, the following vulnerability has been resolved:

usb: typec: hd3ss3220: track VBUS enable state per consumer

regulator_is_enabled() reports the aggregate regulator state, not
whether this consumer holds an enable reference. If another consumer
enables VBUS first, the driver can skip its own regulator_enable() call
and later attempt to drop a reference it never acquired, triggering an
unbalanced regulator disable warning.

Track successful enable and disable calls locally. Keep the state
unchanged when an operation fails so a later role or ID notification
retries the operation while this consumer keeps balanced references.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Resource management flaw leading to kernel unbalanced regulator warnings or system instability
Action: Immediate Patch
AI Analysis

Impact

The flaw lies in the hd3ss3220 driver for USB‑C control in the Linux kernel. When a consumer checks whether VBUS is enabled using regulator_is_enabled(), the function returns an aggregate regulator state that does not distinguish whether the specific consumer holds an enable reference. If another consumer enables VBUS before this one, the hd3ss3220 driver may skip its own regulator_enable() call. Later, when it calls regulator_disable(), it attempts to drop a reference that was never acquired, triggering an unbalanced regulator disable warning in the kernel. This incorrect reference counting is a pure resource‑management bug; it does not provide direct privilege escalation or data disclosure. However, the warning can indicate that the kernel’s regulator subsystem is in an inconsistent state, potentially leading to instability if the mis‑balancing persists.

Affected Systems

The flaw affects the Linux kernel itself. Vendor marks only list “Linux:Linux”, and specific version information is not supplied. Any kernel release that includes the hd3ss3220 driver before the patch is vulnerable, regardless of distribution.

Risk and Exploitability

The exploitation probability is low, with an EPSS score of < 1% and no listed public exploits. The issue is not in the CISA KEV catalog, and no CVSS score is provided. Based on the description, the likely attack vector is a physical or local user who repeatedly interacts with a USB‑C device powered via the hd3ss3220 regulator—such as frequent plugging and unplugging of peripherals—although casual use is unlikely to trigger catastrophic failure.

Generated by OpenCVE AI on September 18, 2026 at 08:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply an updated Linux kernel that contains the hd3ss3220 regulator state‑tracking fix
  • Reboot the system after upgrading to load the corrected driver
  • If an immediate kernel upgrade is not possible, avoid frequent VBUS enable/disable cycles by disabling or unplugging the USB‑C device that uses the hd3ss3220 regulator

Generated by OpenCVE AI on September 18, 2026 at 08:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-404
CWE-754

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: usb: typec: hd3ss3220: track VBUS enable state per consumer regulator_is_enabled() reports the aggregate regulator state, not whether this consumer holds an enable reference. If another consumer enables VBUS first, the driver can skip its own regulator_enable() call and later attempt to drop a reference it never acquired, triggering an unbalanced regulator disable warning. Track successful enable and disable calls locally. Keep the state unchanged when an operation fails so a later role or ID notification retries the operation while this consumer keeps balanced references.
Title usb: typec: hd3ss3220: track VBUS enable state per consumer
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:33:30.400Z

Reserved: 2026-09-11T19:38:34.782Z

Link: CVE-2026-90028

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:15.837

Modified: 2026-09-16T11:17:15.837

Link: CVE-2026-90028

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:15:06Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release

  • CWE-754

    Improper Check for Unusual or Exceptional Conditions