Description
In the Linux kernel, the following vulnerability has been resolved:

clk: mediatek: pllfh: Fix IO remapping leak in register_pllfhs error path

When mtk_clk_register_pllfhs function fails to register a PLL, it
unregisters all PLLs and cleans up itself in its error path before
returning, so the function callers don't need to do it.

But contrary to mtk_clk_unregister_pllfhs function, that does almost
the same sequence, it does not free the IO memory mapped on fhctl node,
leading to a leak.

Fix this leak by factorizing the cleanup sequence in a new private
function and use it both mtk_clk_register_pllfhs and
mtk_clk_unregister_pllfhs functions.

Also, change the loop index start value to avoid the -1 operation on
index at each loop.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Resource Exhaustion
Action: Apply Patch
AI Analysis

Impact

This vulnerability exists in the MediaTek clock driver within the Linux kernel. During the error path of the mtk_clk_register_pllfhs function, the driver attempts to clean up registered PLLs but fails to unmap the IO memory assigned to the fhctl node. The missing unmap operation creates a persistent leak of kernel IO memory. If the function continues to be invoked repeatedly or in environments with repeated hardware reinitializations, the cumulative leaked memory can grow until the kernel can no longer map additional resources, potentially leading to instability or denial of service. Affected systems are Linux kernels compiled with the MediaTek clock support present. The patch is integrated into the mainline kernel codebase and applies to all versions of the kernel that include the mtk_clk_register_pllfhs and mtk_clk_unregister_pllfhs routines. Exact version ranges are not specified in the advisory, but any kernel prior to the commit referenced in the advisory is considered vulnerable. The CVSS score is not provided, and the EPSS score is noted to be under 1 %. The vulnerability is not listed in CISA’s KEV catalog. Exploitation would require access to the kernel module subsystem or privileged boot configuration that allows loading of the MediaTek driver, so the likelihood of attack is low in typical non‑root scenarios. Nevertheless, the resource exhaustion effect could impact availability if left unpatched in systems that use the affected drivers frequently.

Affected Systems

The flaw resides in the MediaTek clock driver (mtk_clk) within the Linux kernel. Linux kernel builds that include MediaTek clock support are affected. The advisory does not specify exact version ranges, but any kernel release that contains the mtk_clk_register_pllfhs and mtk_clk_unregister_pllfhs routines prior to the commit referenced in the advisory is considered vulnerable.

Risk and Exploitability

The CVSS score is not disclosed in the advisory, but the EPSS score of less than 1 % indicates a low probability of active exploitation, and the vulnerability is not recorded in CISA’s KEV catalog. Exploitation would require privileged interaction with the kernel, such as loading or reinitializing the MediaTek clock driver, which is typically restricted to system administrators or boot configurations. If an attacker can trigger repeated failures in the register_pllfhs function, the accumulated IO memory leak could exhaust available kernel space, potentially leading to kernel memory exhaustion and a denial‑of‑service. In practice, the threat is limited to environments that frequently load or re‑enable the affected driver.

Generated by OpenCVE AI on September 19, 2026 at 12:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that incorporates the mtk_clk_register_pllfhs and mtk_clk_unregister_pllfhs cleanup changes shown in the advisory.
  • If a kernel update cannot be applied immediately, disable or unload the MediaTek clock driver to prevent further IO memory leaks until the update is available.
  • After applying the patch or disabling the driver, reboot the system or reload the driver to ensure all stale IO mappings are reclaimed and the kernel starts with a clean state.

Generated by OpenCVE AI on September 19, 2026 at 12:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: clk: mediatek: pllfh: Fix IO remapping leak in register_pllfhs error path When mtk_clk_register_pllfhs function fails to register a PLL, it unregisters all PLLs and cleans up itself in its error path before returning, so the function callers don't need to do it. But contrary to mtk_clk_unregister_pllfhs function, that does almost the same sequence, it does not free the IO memory mapped on fhctl node, leading to a leak. Fix this leak by factorizing the cleanup sequence in a new private function and use it both mtk_clk_register_pllfhs and mtk_clk_unregister_pllfhs functions. Also, change the loop index start value to avoid the -1 operation on index at each loop.
Title clk: mediatek: pllfh: Fix IO remapping leak in register_pllfhs error path
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:45.830Z

Reserved: 2026-09-11T19:38:34.814Z

Link: CVE-2026-90422

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:46.770

Modified: 2026-09-17T17:17:46.770

Link: CVE-2026-90422

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T13:00:12Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime