CVE-2026-90360
In the Linux kernel, the following vulnerability has been resolved: regulator: core: use system_freezable_wq for init complete work schedule_delayed_work() uses system_wq, which is non-freezable, allowing regulator_init_complete_work to run concurrently with system suspend. This work fires ~30s after boot to disable unused regulators via I2C. When it races with PM suspend, the I2C adapter may already be suspended, triggering a -ESHUTDOWN warning in __i2c_transfer(): WARNING: ... at __i2c_transfer+0x36c/0x3c8 Call trace: __i2c_transfer i2c_transfer regmap_i2c_write _regmap_update_bits regulator_disable_regmap _regulator_do_disable regulator_late_cleanup regulator_init_complete_work_function process_one_work Switch to system_freezable_wq so the work is frozen before any device is suspended, eliminating the race.
Affected versions
Linux kernel versions
4.9.195,
4.14.147,
4.19.77,
5.2.19,
5.3.4,
5.4
and later are affected. Fixed in
4.9.207,
4.14.160,
5.10.270,
5.15.221,
6.1.188,
6.6.157,
6.12.110,
6.18.52,
7.2.6,
7.3-rc1
and their respective stable series.
References
10 totalFrequently asked questions
-
What is CVE-2026-90360?
CVE-2026-90360 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 4.9.195 onward and has been patched in 4.9.207, 4.14.160, 5.10.270 and others. CVE-2026-90360 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
Is there a patch available for CVE-2026-90360?
Yes. CVE-2026-90360 has been patched. Fixed versions include 4.9.207, 4.14.160, 5.10.270 and others. If you are running Linux kernel 4.9.195 or later up to the fix versions, apply the relevant patch for your kernel branch.
-
Is CVE-2026-90360 actively exploited?
No. CVE-2026-90360 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.