CVE-2026-89936
CVE CVE-2026-89936EUVD EUVD-2026-80536Published 2026-09-16T10:32:25.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: iio: dac: m62332: Fix regulator reference count imbalance m62332_set_value() enables the Vcc regulator on every write of a non-zero value and disables it on every write of zero, without tracking the channel's current state. Because the regulator is reference counted, changing a channel directly from one non-zero value to another enables it more than once, while a later write of zero disables it only once. The reference count never returns to zero and the regulator is left enabled indefinitely. Only enable the regulator on the transition from zero to non-zero, and only disable it on the transition from non-zero to zero, using the previously stored channel value to detect the edge. Balance the regulator on the I2C error path so the reference count stays consistent if the write fails.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 7.2.5; patch: 6.6.157; patch: 7.3-rc1; b87b0c0f81e8d11c881b726b886b7502ab67d884 <08ac8d2976d57aa943d64e351c4d0bd8bb0c6de9; b87b0c0f81e8d11c881b726b886b7502ab67d884 <bac0ed8bee651aa841375edf72c6ab1d10ac80c6; b87b0c0f81e8d11c881b726b886b7502ab67d884 <ae18d2d2ef27a4d04fda6e30c23774513dc9be1e; patch: 6.18.51; b87b0c0f81e8d11c881b726b886b7502ab67d884 <a130404ce0b69ca1438126bd81c1985d3b4d2e6f; b87b0c0f81e8d11c881b726b886b7502ab67d884 <f5acb824277a97a5210c454872202bf7f08c75d4; patch: 6.12.110; patch: 0; b87b0c0f81e8d11c881b726b886b7502ab67d884 <9263b9ad968a563337a60e0eb66e35186e1faf9a; patch: 5.10.270; 4.2; patch: 6.1.188; b87b0c0f81e8d11c881b726b886b7502ab67d884 <1d3a7d7dd3adee19e00be2b2237140f0fe169484; patch: 5.15.221; b87b0c0f81e8d11c881b726b886b7502ab67d884 <9fe22f563b2a0fdb11fd3711a8c39c023629c08a
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.