CVE-2026-93272
In the Linux kernel, the following vulnerability has been resolved: remoteproc: qcom_wcnss: Fix handling the lack of PD regulators in v3 The changes introduced to handle single power domain platforms have swapped the info pointer increment from num_pd_vregs to num_pds, which would shift the info pointer past the end of the array for pronto-v3, which does not list power domain regulators in vregs. This showed up as a difference between GCC- and LLVM-compiled kernels on SDM632 devices, where only with LLVM one would get the "regulator request with no identifier" error, because the out-of-bounds memory ended up being zeroed. Fix by skipping the increment when there are more power domains than regulators.
Affected versions
Linux kernel versions
5.15.185,
6.1.141,
6.6.93,
6.12.31,
6.14.9,
6.15
and later are affected. Fixed in
7.2.6,
7.3-rc1
and their respective stable series.
References
2 totalFrequently asked questions
-
What is CVE-2026-93272?
CVE-2026-93272 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 5.15.185 onward and has been patched in 7.2.6 and 7.3-rc1. CVE-2026-93272 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
Is there a patch available for CVE-2026-93272?
Yes. CVE-2026-93272 has been patched. Fixed versions include 7.2.6 and 7.3-rc1. If you are running Linux kernel 5.15.185 or later up to the fix versions, apply the relevant patch for your kernel branch.
-
Is CVE-2026-93272 actively exploited?
No. CVE-2026-93272 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.