Description
In the Linux kernel, the following vulnerability has been resolved:

clk: visconti: Make sure clk_init_data is fully initialized

The clk_init_data structure contains several mutually-exclusive members
for different methods to specify the possible parents of a clock,
prompting drivers to initialize only the members they need. However,
not initializing all members may cause subtle issues, which are only
exposed when CONFIG_INIT_STACK_ALL_PATTERN or CONFIG_INIT_STACK_NONE is
enabled.

visconti_clk_register_gate() fills in init.parent_data, and assumes that
init.parent_names is NULL. However, the latter in uninitialized, and
thus may cause a crash.

Make sure all members are fully initialized, to fix such bugs, and to
avoid future breakage when converting drivers to a different method for
specifying the parents.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via kernel crash
Action: Immediate Patch
AI Analysis

Impact

The visconti clock driver in the Linux kernel relies on the clk_init_data structure. The driver populates only the members it needs, leaving other mutually exclusive fields uninitialized. When certain kernel configurations that fill the stack with patterns are enabled, the uninitialized fields contain garbage values that the driver later assumes are NULL. The driver dereferences these values during clock registration, causing a kernel panic that takes the system offline. The weakness is an improper initialization of a data structure (CWE‑665).

Affected Systems

All systems running a Linux kernel that includes the visconti clock driver and is compiled with the buggy clk_init_data handling code. The issue exists in any kernel version containing the problematic code path; no specific release version is mentioned, so current kernels and potentially older builds are affected until the fix is applied.

Risk and Exploitability

The probability of exploitation is very low, as reflected by an EPSS score of less than 1%, and the vulnerability is not listed in the CISA KEV catalog. The crash‑based impact delivers a full denial of service for the affected system, yet an attacker would require local access to load the buggy driver or to enable the vulnerable configuration options (CONFIG_INIT_STACK_ALL_PATTERN or CONFIG_INIT_STACK_NONE). Consequently, the overall risk is moderate to high for availability, with the primary mitigation being to apply the vendor patch or rebuild with the problematic options disabled.

Generated by OpenCVE AI on September 20, 2026 at 03:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that fully initializes clk_init_data, such as the commit 0e97c22b or any later kernel release that incorporates this change.
  • If a kernel upgrade is not possible, rebuild the kernel disabling the CONFIG_INIT_STACK_ALL_PATTERN and CONFIG_INIT_STACK_NONE options to eliminate the uninitialized field problem.
  • Consult your distribution’s security advisories for vendor‑specific backports or custom patches and apply them when available.

Generated by OpenCVE AI on September 20, 2026 at 03:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: clk: visconti: Make sure clk_init_data is fully initialized The clk_init_data structure contains several mutually-exclusive members for different methods to specify the possible parents of a clock, prompting drivers to initialize only the members they need. However, not initializing all members may cause subtle issues, which are only exposed when CONFIG_INIT_STACK_ALL_PATTERN or CONFIG_INIT_STACK_NONE is enabled. visconti_clk_register_gate() fills in init.parent_data, and assumes that init.parent_names is NULL. However, the latter in uninitialized, and thus may cause a crash. Make sure all members are fully initialized, to fix such bugs, and to avoid future breakage when converting drivers to a different method for specifying the parents.
Title clk: visconti: Make sure clk_init_data is fully initialized
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:25.910Z

Reserved: 2026-09-11T19:38:34.788Z

Link: CVE-2026-90122

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:04.420

Modified: 2026-09-17T17:17:04.420

Link: CVE-2026-90122

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T03:45:12Z

Weaknesses