Description
In the Linux kernel, the following vulnerability has been resolved:

phy: sunplus: fix error handling in sp_uphy_init()

Fix the error paths of sp_uphy_init() to undo exactly what each stage
did: return directly if clk_prepare_enable() fails, release only the clock
if reset_control_deassert() fails, and jump to err_reset if
update_disc_vol() fails so the clock and reset are not leaked.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Resource Leak and Potential Driver Instability
Action: Patch Kernel
AI Analysis

Impact

An improper error handling sequence in the Sunplus PHY driver’s initialization routine caused resources such as clocks and reset controls to remain allocated when failures occurred. This flaw could lead to resource exhaustion or unpredictable driver state, potentially affecting system stability. The patch restores the correct cleanup paths by returning immediately on clock‑enable failure, releasing the clock only if reset deassertion fails, and jumping to an error handler when voltage update fails, ensuring that no resources are leaked. The primary impact is therefore a resource leak that may manifest as driver instability or degraded performance.

Affected Systems

The vulnerability is present in any Linux kernel that includes the Sunplus PHY driver without the recent fix. No specific kernel version is listed in the CVE data, but the fix is attached to commit 1489b694b1f3265cd5363100642a22190033f4b0 (and related commits). Users running kernels that contain this commit are not affected.

Risk and Exploitability

The EPSS score is reported as <1 %, indicating a very low likelihood of exploitation in the wild. The vulnerability is not catalogued in the CISA KEV list. While the flaw is not immediately exploitable as a pure attack vector, an attacker with local or kernel privileges could trigger the initialization path to consume resources iteratively, potentially causing a denial of service. It is inferred that an attacker would need to exercise local privileged or kernel mode execution to trigger the Sunplus PHY driver’s initialization routine, as the issue resides entirely within the kernel driver. Consequently, the risk is low but non‑zero, and patching is recommended.

Generated by OpenCVE AI on September 20, 2026 at 01:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade your Linux kernel to a version that includes the Sunplus PHY driver fix (commit 1489b694b1f3265cd5363100642a22190033f4b0).
  • If a kernel upgrade is not immediately possible, monitor for Sunplus PHY driver failures and reboot the system if instability occurs, as a temporary mitigation.
  • When building custom kernels or modules, rebuild them against the updated kernel source so that module symbols and dependencies reflect the fixed driver.

Generated by OpenCVE AI on September 20, 2026 at 01:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401
CWE-775

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: phy: sunplus: fix error handling in sp_uphy_init() Fix the error paths of sp_uphy_init() to undo exactly what each stage did: return directly if clk_prepare_enable() fails, release only the clock if reset_control_deassert() fails, and jump to err_reset if update_disc_vol() fails so the clock and reset are not leaked.
Title phy: sunplus: fix error handling in sp_uphy_init()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:16.004Z

Reserved: 2026-09-11T19:38:34.798Z

Link: CVE-2026-90287

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:25.733

Modified: 2026-09-17T17:17:25.733

Link: CVE-2026-90287

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:30:16Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime

  • CWE-775

    Missing Release of File Descriptor or Handle after Effective Lifetime