Description
In the Linux kernel, the following vulnerability has been resolved:

clk: devres: fix cleanup in devm_clk_get_optional_enabled_with_rate()

devm_clk_get_optional_enabled_with_rate() registers its cleanup action
before setting the clock rate. If setting the rate fails, it attempts to
disable and unprepare a clock that was never enabled. This issue was
spotted while reviewing "rust: clk: add devres-managed clks" [1].

Register the cleanup action only after successfully preparing and enabling
the clock.

[1]: https://lore.kernel.org/rust-for-linux/20260706-clk-type-state-v5-3-67c5f326a16c@collabora.com
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel panic or denial of service from improper clock cleanup
Action: Immediate Patch
AI Analysis

Impact

In the Linux kernel, the function devm_clk_get_optional_enabled_with_rate() registered its cleanup action before successfully preparing and enabling the clock. When setting the clock rate fails, the cleanup routine mistakenly attempts to disable and unprepare a clock that was never enabled, which can corrupt the clock state and trigger a kernel crash. This flaw represents an improper release of resources and can lead to system instability or denial of service. The vulnerability is specific to the clock driver subsystem and involves mismatched resource management. Attackers could exploit this by provoking resource failures through a driver or module that calls the affected function, potentially resulting in a crash. The flaw falls under the category of improper resource release and can affect any Linux kernel version that contains the bug before the provided fix was merged.

Affected Systems

The issue resides in the Linux kernel code path for devm_clk_get_optional_enabled_with_rate(). No specific release range is listed, implying that any kernel built from the repository before the patch commit is vulnerable. The patch referenced in the references resolves the issue, so kernels incorporating that commit or any later stable release that contains the change should be safe. Systems running older or custom kernel builds that have not applied this change remain at risk. Because the bug occurs in a core kernel subsystem, all userspace components that rely on the clock framework—including device drivers, device tree overlays, and kernel modules—may indirectly invoke the problematic code. Therefore, any system that loads a driver calling this function could be affected. The EPSS score is less than 1 %, indicating a very low probability of exploitation at the time of analysis, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, the potential impact of a kernel panic warrants attention. The attack vector likely requires that the attacker can trigger a failure in setting the clock rate, which may be achieved through a compromised or malicious device driver or kernel module. Given that no publicly available exploit scripts are known, the risk remains theoretical but should be mitigated promptly to avoid future exploitation once an attacker discovers a suitable trigger.

Risk and Exploitability

Unpatched kernels may experience a kernel panic or intermittent failures when the cleanup path is invoked following a failed clock‑rate set. The flaw caused the cleanup routine to disable a clock that had never been enabled, potentially corrupting clock state. The EPSS score is less than 1 % and the vulnerability is not present in CISA KEV, indicating a low current exploitation probability. Nevertheless, the consequence of a kernel crash is severe, compromising system availability, and the flaw is confined to the clock management subsystem. Attackers would need to provoke the rate‑setting failure, possibly by a malicious kernel module or driver that calls devm_clk_get_optional_enabled_with_rate().

Generated by OpenCVE AI on September 20, 2026 at 02:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel update that includes the commit c/0d4d262c1664365e17e0a5ba2ab79f4db484b44e that corrects the cleanup sequence
  • Recompile or install the patched kernel image and reboot into the updated kernel
  • If an immediate kernel upgrade is not feasible, disable or replace any drivers that invoke devm_clk_get_optional_enabled_with_rate() until a patched kernel is available
  • Monitor dmesg and system logs for any CLOCK related warnings or unexpected failures after the update

Generated by OpenCVE AI on September 20, 2026 at 02:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-754

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: clk: devres: fix cleanup in devm_clk_get_optional_enabled_with_rate() devm_clk_get_optional_enabled_with_rate() registers its cleanup action before setting the clock rate. If setting the rate fails, it attempts to disable and unprepare a clock that was never enabled. This issue was spotted while reviewing "rust: clk: add devres-managed clks" [1]. Register the cleanup action only after successfully preparing and enabling the clock. [1]: https://lore.kernel.org/rust-for-linux/20260706-clk-type-state-v5-3-67c5f326a16c@collabora.com
Title clk: devres: fix cleanup in devm_clk_get_optional_enabled_with_rate()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:42.342Z

Reserved: 2026-09-11T19:38:34.789Z

Link: CVE-2026-90147

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:07.603

Modified: 2026-09-17T17:17:07.603

Link: CVE-2026-90147

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T03:00:11Z

Weaknesses
  • CWE-754

    Improper Check for Unusual or Exceptional Conditions