Description
In the Linux kernel, the following vulnerability has been resolved:

rtc: pcf8563: fix clock provider leak on unbind

pcf8563_clkout_register_clk() registers the CLKOUT clock provider with
of_clk_add_provider(), but nothing ever unwinds it: there is no
of_clk_del_provider() call and the driver has no remove callback. Each
of_clk_add_provider() allocates a struct of_clk_provider, takes a
reference on the OF node and adds an entry to the global of_clk_providers
list, none of which is released when the device is unbound. Every
bind/unbind (or module reload) therefore leaks a provider structure and
an of_node reference.

The clock itself is already device-managed (devm_clk_register()); only
the provider registration was not. Use devm_of_clk_add_hw_provider() so
the provider is removed automatically on unbind. Tie it to the parent
i2c device, whose OF node carries the #clock-cells and clock-output-names
properties (the RTC class device has no OF node of its own).
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (resource exhaustion)
Action: Patch Now
AI Analysis

Impact

A flaw in the Linux kernel’s PCF8563 clock driver causes it to register a clock provider during device bind but never unregister that provider during unbind. Each bind/unbind allocates a provider structure, holds a reference to the device tree node, and adds the provider to a global list, with none of these resources released when the device is unbound. Over repeated bind/unbind cycles—such as during hotplug events or module reloads—these orphaned structures accumulate, consuming kernel memory and increasing the reference count of the node. The vulnerability does not disclose data or enable arbitrary code execution but can lead to resource exhaustion and eventual system instability or a denial‑of‑service outcome once memory limits are reached. The weakness aligns with a memory/resource leak type of vulnerability.

Affected Systems

All Linux kernel releases containing the PCF8563 RTC driver before the upstream fix is applied. The exact affected kernel versions are not enumerated in the CVE record, but the issue is present in every kernel that includes the unbound driver implementation.

Risk and Exploitability

The CVSS score is unspecified, but the EPSS score indicates exploitation odds below 1%, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack vector requires local privilege to force reloads or trigger device hotplug events that cause the driver to unbind, making remote exploitation improbable. Consequently, the practical risk is a low‑to‑moderate likelihood of a denial‑of‑service event in environments where many RTC instances are bound and unbound over time.

Generated by OpenCVE AI on September 20, 2026 at 03:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply an updated kernel version that includes the pcf8563 clock provider unbind fix.
  • Disable automatic hotplug or driver reload for the PCF8563 device to prevent repeated unbind leaks (for example, block the kernel module or adjust system service settings).
  • If disabling the driver is infeasible, remove the PCF8563 device from the device tree or replace it with a dummy driver so that it never binds.

Generated by OpenCVE AI on September 20, 2026 at 03:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: rtc: pcf8563: fix clock provider leak on unbind pcf8563_clkout_register_clk() registers the CLKOUT clock provider with of_clk_add_provider(), but nothing ever unwinds it: there is no of_clk_del_provider() call and the driver has no remove callback. Each of_clk_add_provider() allocates a struct of_clk_provider, takes a reference on the OF node and adds an entry to the global of_clk_providers list, none of which is released when the device is unbound. Every bind/unbind (or module reload) therefore leaks a provider structure and an of_node reference. The clock itself is already device-managed (devm_clk_register()); only the provider registration was not. Use devm_of_clk_add_hw_provider() so the provider is removed automatically on unbind. Tie it to the parent i2c device, whose OF node carries the #clock-cells and clock-output-names properties (the RTC class device has no OF node of its own).
Title rtc: pcf8563: fix clock provider leak on unbind
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:28.568Z

Reserved: 2026-09-11T19:38:34.788Z

Link: CVE-2026-90126

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:04.937

Modified: 2026-09-17T17:17:04.937

Link: CVE-2026-90126

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T03:45:12Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime