0.0
NA
CVE-2026-90360
regulator: core: use system_freezable_wq for init complete work
Description

In the Linux kernel, the following vulnerability has been resolved: regulator: core: use system_freezable_wq for init complete work schedule_delayed_work() uses system_wq, which is non-freezable, allowing regulator_init_complete_work to run concurrently with system suspend. This work fires ~30s after boot to disable unused regulators via I2C. When it races with PM suspend, the I2C adapter may already be suspended, triggering a -ESHUTDOWN warning in __i2c_transfer(): WARNING: ... at __i2c_transfer+0x36c/0x3c8 Call trace: __i2c_transfer i2c_transfer regmap_i2c_write _regmap_update_bits regulator_disable_regmap _regulator_do_disable regulator_late_cleanup regulator_init_complete_work_function process_one_work Switch to system_freezable_wq so the work is frozen before any device is suspended, eliminating the race.

INFO

Published Date :

Sept. 17, 2026, 5:17 p.m.

Last Modified :

Sept. 17, 2026, 5:17 p.m.

Remotely Exploit :

No

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-90360 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Linux linux_kernel
Solution
Use a freezable workqueue to prevent race conditions during system suspend.
  • Switch to system_freezable_wq for regulator init completion.
  • Ensure work is frozen before device suspend.
  • Update the Linux kernel to the latest version.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-90360 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-90360 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-90360 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-90360 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Sep. 17, 2026

    Action Type Old Value New Value
    Added Description In the Linux kernel, the following vulnerability has been resolved: regulator: core: use system_freezable_wq for init complete work schedule_delayed_work() uses system_wq, which is non-freezable, allowing regulator_init_complete_work to run concurrently with system suspend. This work fires ~30s after boot to disable unused regulators via I2C. When it races with PM suspend, the I2C adapter may already be suspended, triggering a -ESHUTDOWN warning in __i2c_transfer(): WARNING: ... at __i2c_transfer+0x36c/0x3c8 Call trace: __i2c_transfer i2c_transfer regmap_i2c_write _regmap_update_bits regulator_disable_regmap _regulator_do_disable regulator_late_cleanup regulator_init_complete_work_function process_one_work Switch to system_freezable_wq so the work is frozen before any device is suspended, eliminating the race.
    Added Affected New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/90xxx/CVE-2026-90360.json">CVE-2026-90360</a>
    Added Reference https://git.kernel.org/stable/c/03eab318cedd6ae34ecd34533cd986edf5237164
    Added Reference https://git.kernel.org/stable/c/0b950aa7ec95e120b2bde745ca9a7ed3ce49d528
    Added Reference https://git.kernel.org/stable/c/0d23d658d79925076026fff62a49b8c94e0e8922
    Added Reference https://git.kernel.org/stable/c/29dc2e24f6adb36dcb884acf455644c397a67471
    Added Reference https://git.kernel.org/stable/c/2cebc00340a585adeffe321bc41f1937eb79a4dc
    Added Reference https://git.kernel.org/stable/c/350a0cba90e1bd40b1fe5b396923d2f3a61d1056
    Added Reference https://git.kernel.org/stable/c/6d0a2c5e210f2fba099129e6183ef81316a6ae48
    Added Reference https://git.kernel.org/stable/c/8a2ae3ab348cce44120667277c2198f10cc348b1
    Added Reference https://git.kernel.org/stable/c/9cf65270c1c1717c84dcfacd58a782c1186b0cbf
    Added Reference https://git.kernel.org/stable/c/dc8570a5b830190bf0b57017c35aef97cd6ad7d9
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.