0.0
NA
CVE-2026-90126
rtc: pcf8563: fix clock provider leak on unbind
Description

In the Linux kernel, the following vulnerability has been resolved: rtc: pcf8563: fix clock provider leak on unbind pcf8563_clkout_register_clk() registers the CLKOUT clock provider with of_clk_add_provider(), but nothing ever unwinds it: there is no of_clk_del_provider() call and the driver has no remove callback. Each of_clk_add_provider() allocates a struct of_clk_provider, takes a reference on the OF node and adds an entry to the global of_clk_providers list, none of which is released when the device is unbound. Every bind/unbind (or module reload) therefore leaks a provider structure and an of_node reference. The clock itself is already device-managed (devm_clk_register()); only the provider registration was not. Use devm_of_clk_add_hw_provider() so the provider is removed automatically on unbind. Tie it to the parent i2c device, whose OF node carries the #clock-cells and clock-output-names properties (the RTC class device has no OF node of its own).

INFO

Published Date :

Sept. 17, 2026, 5:17 p.m.

Last Modified :

Sept. 17, 2026, 5:17 p.m.

Remotely Exploit :

No

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-90126 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Linux linux_kernel
Solution
Automatically remove the clock provider on unbind using devm_of_clk_add_hw_provider.
  • Use devm_of_clk_add_hw_provider for automatic provider removal.
  • Ensure the provider is tied to the parent I2C device.
  • Update the Linux kernel to include the fix.
  • Rebuild and deploy the updated kernel.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-90126 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-90126 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-90126 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-90126 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Sep. 17, 2026

    Action Type Old Value New Value
    Added Description In the Linux kernel, the following vulnerability has been resolved: rtc: pcf8563: fix clock provider leak on unbind pcf8563_clkout_register_clk() registers the CLKOUT clock provider with of_clk_add_provider(), but nothing ever unwinds it: there is no of_clk_del_provider() call and the driver has no remove callback. Each of_clk_add_provider() allocates a struct of_clk_provider, takes a reference on the OF node and adds an entry to the global of_clk_providers list, none of which is released when the device is unbound. Every bind/unbind (or module reload) therefore leaks a provider structure and an of_node reference. The clock itself is already device-managed (devm_clk_register()); only the provider registration was not. Use devm_of_clk_add_hw_provider() so the provider is removed automatically on unbind. Tie it to the parent i2c device, whose OF node carries the #clock-cells and clock-output-names properties (the RTC class device has no OF node of its own).
    Added Affected New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/90xxx/CVE-2026-90126.json">CVE-2026-90126</a>
    Added Reference https://git.kernel.org/stable/c/08a59c28c2bdbcd655e99526c86a41dc83834283
    Added Reference https://git.kernel.org/stable/c/2b5622cf4ee218b6f98d31dbf3fbd44b9b6bd675
    Added Reference https://git.kernel.org/stable/c/30b7c63af50fe1464e7582a37de1ca4bd030ecc1
    Added Reference https://git.kernel.org/stable/c/36cb00c33bd83e7ce31b5a9f1f7c70db0cb7776c
    Added Reference https://git.kernel.org/stable/c/6218c0533a72235ec9c5f41b812c63d963bd4a3e
    Added Reference https://git.kernel.org/stable/c/7afb8db47c4f107bce89cfe5115fb31ba7c94665
    Added Reference https://git.kernel.org/stable/c/97edf3fd9a46ea89a167966991c0449cfa07b36f
    Added Reference https://git.kernel.org/stable/c/9c48a53685040bb0de45a640b34055cbbfc69d4f
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.