Description
In the Linux kernel, the following vulnerability has been resolved:

clk: qcom: gdsc: tear down per-domain genpds in gdsc_unregister()

gdsc_unregister() removes the OF provider entry and tears down the
parent/subdomain wiring, but never calls pm_genpd_remove() on the
individual generic_pm_domain structures registered by gdsc_init():

void gdsc_unregister(struct gdsc_desc *desc)
{
struct device *dev = desc->dev;
size_t num = desc->num;

gdsc_pm_subdomain_remove(desc, num);
of_genpd_del_provider(dev->of_node);
}

That leaves dangling entries on the global gpd_list. After a provider
unbind/rebind cycle (deferred-probe replay during early boot, real
module unload of a clk driver that owns GDSCs, or an OF-overlay tear-
down) the next gdsc_init() will end up trying to re-register a name
that is still in the list and pm_genpd_init() returns -EEXIST.

While we are here, flip the order so the consumer-facing OF provider
entry is the first thing removed -- otherwise a fresh
of_genpd_get_from_provider() call racing with the teardown could
attach to a domain that is mid-removal.

Iterate the scs[] array and pm_genpd_remove() each registered domain
after the subdomain links are torn down. The regulators stay devm-
managed (devm_regulator_get_optional() in gdsc_register()), so the
release happens automatically when the underlying device is unbound;
just the genpd accounting needs to be undone explicitly.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

In the Linux kernel, the gdsc_unregister function fails to remove generic power domains that were registered during gdsc_init. This omission leaves dangling entries in the global gpd_list. When a driver that owns GDSCs is unloaded and later reloaded, the subsequent gdsc_init attempts to re‑register a domain that is already present, causing pm_genpd_init to return –EEXIST and resulting in a registration failure. The error can propagate up to device tree parsing or runtime driver loading, potentially leading to service interruption or a kernel warning/exception. The weakness involved is improper resource cleanup, which falls under the category of resource management faults.

Affected Systems

The flaw appears in all Linux kernel builds containing the Qualcomm generic power domain (GDsc) infrastructure. No specific kernel version range is listed, meaning the vulnerability applies to any kernel prior to the commit that introduced the fix. The affected code resides in the clock driver subsystem for Qualcomm devices, so any system that loads the corresponding clk driver modules (e.g., on Snapdragon or other QCOM SoCs) is potentially impacted.

Risk and Exploitability

The EPSS score is reported as less than 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a very low likelihood of exploitation in the wild. However, because the flaw can be triggered by a normal unload/rebind cycle of a kernel module, a local privileged user or a device manager with module unloading capability could reproducibly cause the error, leading to degraded system availability or a reboot loop. The lack of a public exploit suggests that the primary threat is internal or testing rather than external, but the impact on service continuity warrants a timely kernel update.

Generated by OpenCVE AI on September 19, 2026 at 07:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the kernel to a revision that includes the commit fixing gdsc_unregister. This is the authoritative fix.
  • If an update is not yet available, avoid unloading and reloading Qualcomm clock driver modules during normal operation; perform any necessary module workarounds only during system maintenance windows and after a reboot, so that the gpd_list can be cleaned up cleanly.
  • Monitor dmesg and kernel logs for messages such as ‘pm_genpd_init: failed with -EEXIST’ or any GDsc‑related warnings, and trigger a reboot if these errors are detected to force the clean state.

Generated by OpenCVE AI on September 19, 2026 at 07:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401
CWE-772

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: clk: qcom: gdsc: tear down per-domain genpds in gdsc_unregister() gdsc_unregister() removes the OF provider entry and tears down the parent/subdomain wiring, but never calls pm_genpd_remove() on the individual generic_pm_domain structures registered by gdsc_init(): void gdsc_unregister(struct gdsc_desc *desc) { struct device *dev = desc->dev; size_t num = desc->num; gdsc_pm_subdomain_remove(desc, num); of_genpd_del_provider(dev->of_node); } That leaves dangling entries on the global gpd_list. After a provider unbind/rebind cycle (deferred-probe replay during early boot, real module unload of a clk driver that owns GDSCs, or an OF-overlay tear- down) the next gdsc_init() will end up trying to re-register a name that is still in the list and pm_genpd_init() returns -EEXIST. While we are here, flip the order so the consumer-facing OF provider entry is the first thing removed -- otherwise a fresh of_genpd_get_from_provider() call racing with the teardown could attach to a domain that is mid-removal. Iterate the scs[] array and pm_genpd_remove() each registered domain after the subdomain links are torn down. The regulators stay devm- managed (devm_regulator_get_optional() in gdsc_register()), so the release happens automatically when the underlying device is unbound; just the genpd accounting needs to be undone explicitly.
Title clk: qcom: gdsc: tear down per-domain genpds in gdsc_unregister()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:43.421Z

Reserved: 2026-09-17T16:02:15.088Z

Link: CVE-2026-93145

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:09.610

Modified: 2026-09-17T17:18:09.610

Link: CVE-2026-93145

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T16:45:16Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime

  • CWE-772

    Missing Release of Resource after Effective Lifetime