Description
In the Linux kernel, the following vulnerability has been resolved:

regulator: core: use system_freezable_wq for init complete work

schedule_delayed_work() uses system_wq, which is non-freezable, allowing
regulator_init_complete_work to run concurrently with system suspend. This
work fires ~30s after boot to disable unused regulators via I2C. When it
races with PM suspend, the I2C adapter may already be suspended, triggering
a -ESHUTDOWN warning in __i2c_transfer():

WARNING: ... at __i2c_transfer+0x36c/0x3c8
Call trace:
__i2c_transfer
i2c_transfer
regmap_i2c_write
_regmap_update_bits
regulator_disable_regmap
_regulator_do_disable
regulator_late_cleanup
regulator_init_complete_work_function
process_one_work

Switch to system_freezable_wq so the work is frozen before any device
is suspended, eliminating the race.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel instability due to a race condition during system suspend
Action: Immediate patch
AI Analysis

Impact

The flaw originates from a race condition in the regulator subsystem of the Linux kernel. A delayed work task intended to disable unused I2C‑controlled regulators runs on a non‑freezable work queue, allowing it to execute while the system is in the middle of a suspend transition. When this task attempts to write to a device via I2C after the adapter has already been suspended, the kernel generates a warning and can potentially leave the device or regulator in an inconsistent state, leading to functional degradation or system instability.

Affected Systems

The issue affects the generic Linux kernel, as indicated by the vendor and product names. No specific kernel version range is provided, so any kernel that contains the affected code path before the patch may be vulnerable.

Risk and Exploitability

The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of exploitation. The race condition requires the system to be transitioning to suspend, limiting the attack scenarios to a local boot or power cycle that occurs during that window. While exploitation is unlikely, the impact on service availability can still be significant on vulnerable systems.

Generated by OpenCVE AI on September 19, 2026 at 14:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that contains the patch for the regulator scheduling issue
  • Reboot the system after applying the new kernel so the work queue is initialized correctly
  • Continuously monitor kernel logs for i2c_transfer or regulator warning messages to confirm the issue is resolved

Generated by OpenCVE AI on September 19, 2026 at 14:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: regulator: core: use system_freezable_wq for init complete work schedule_delayed_work() uses system_wq, which is non-freezable, allowing regulator_init_complete_work to run concurrently with system suspend. This work fires ~30s after boot to disable unused regulators via I2C. When it races with PM suspend, the I2C adapter may already be suspended, triggering a -ESHUTDOWN warning in __i2c_transfer(): WARNING: ... at __i2c_transfer+0x36c/0x3c8 Call trace: __i2c_transfer i2c_transfer regmap_i2c_write _regmap_update_bits regulator_disable_regmap _regulator_do_disable regulator_late_cleanup regulator_init_complete_work_function process_one_work Switch to system_freezable_wq so the work is frozen before any device is suspended, eliminating the race.
Title regulator: core: use system_freezable_wq for init complete work
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:04.861Z

Reserved: 2026-09-11T19:38:34.806Z

Link: CVE-2026-90360

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:34.913

Modified: 2026-09-17T17:17:34.913

Link: CVE-2026-90360

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T15:00:12Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')