Description
In the Linux kernel, the following vulnerability has been resolved:

bus: mhi: host: Fix controller cleanup on EDL sysfs failure

mhi_register_controller() adds the controller device before creating the
optional trigger_edl sysfs file. If sysfs_create_file() fails, the error
path only drops the device reference and leaves the device registered.

Hence, call device_del() in the error path before put_device().
Published: 2026-09-17
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Dangling MHI device registration can lead to resource exhaustion or system instability
Action: Apply patch
AI Analysis

Impact

The vulnerability is in the Linux kernel MHI host driver. When a controller is registered, the driver creates a device instance and then attempts to add an optional trigger edl sysfs file. If the sysfs creation fails, the code drops only the device reference but leaves the device registered, resulting in a dangling registration that can cause resource leakage or instability during subsequent driver operations.

Affected Systems

Affected systems include all versions of the Linux kernel that contain the unpatched MHI host driver before the commit that added cleanup logic. The issue is present in every distribution build that employs the buggy registration code and is not limited to a particular release series.

Risk and Exploitability

The CVSS score of 7 indicates a high severity, but the EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, implying a low likelihood of current exploitation. Based on the description, it is inferred that an attacker would need local or privileged access, such as the ability to load a kernel module or manipulate the MHI subsystem, to repeatedly trigger the faulty registration path. If achieved, repeated failures could exhaust kernel resources or lead to driver instability, potentially resulting in a denial‑of‑service condition.

Generated by OpenCVE AI on September 20, 2026 at 01:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a revision that includes the mhi_register_controller fix from the linked commits.
  • If an upgrade is not immediately possible, reboot the system to clear any stale MHI device entries and monitor system logs for sysfs creation failures.
  • Restrict write permissions to MHI subsystem sysfs entries to trusted administrators to reduce accidental or malicious triggering of the registration fault.

Generated by OpenCVE AI on September 20, 2026 at 01:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772

Sat, 19 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: bus: mhi: host: Fix controller cleanup on EDL sysfs failure mhi_register_controller() adds the controller device before creating the optional trigger_edl sysfs file. If sysfs_create_file() fails, the error path only drops the device reference and leaves the device registered. Hence, call device_del() in the error path before put_device().
Title bus: mhi: host: Fix controller cleanup on EDL sysfs failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:55:09.459Z

Reserved: 2026-09-11T19:38:34.811Z

Link: CVE-2026-90402

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:39.987

Modified: 2026-09-18T18:17:57.490

Link: CVE-2026-90402

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:45:17Z

Weaknesses

No weakness.