CVE-2026-90027 is a vulnerability in Linux Kernel
Published on September 16, 2026
usb: typec: qcom-pmic-typec: disable cc_debounce_dwork on stop
In the Linux kernel, the following vulnerability has been resolved:
usb: typec: qcom-pmic-typec: disable cc_debounce_dwork on stop
cc_debounce_dwork is queued from the set_cc() and start_toggling()
callbacks, which run from TCPM's kthread worker. port_stop() returns
before tcpm_unregister_port() destroys that worker. Flushing the worker
during unregister may therefore run a callback which queues the delayed
work after port_stop() has returned.
The delayed work can then run after devres has freed pmic_typec_port.
Use disable_delayed_work_sync() in port_stop() to cancel a pending
instance and prevent the TCPM callbacks from queueing another one.
This issue was found by an in-house static analysis tool.
Products Associated with CVE-2026-90027
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version a4422ff221429c600c3dc5d0394fb3738b89d040 and below 4359b5f95c93a4658e08368fa6fab9d89eb98447 is affected.
- Version a4422ff221429c600c3dc5d0394fb3738b89d040 and below c614d7c44ca7fb78867ba46b233acdb59287e8c8 is affected.
- Version a4422ff221429c600c3dc5d0394fb3738b89d040 and below 1ab669c2b44e1040ddfab7cd7f717aad580d17aa is affected.
- Version a4422ff221429c600c3dc5d0394fb3738b89d040 and below 263f7d61a4201cde16849b2d016251806e7418be is affected.
- Version 6.5 is affected.
- Before 6.5 is unaffected.
- Version 6.12.110, <= 6.12.* is unaffected.
- Version 6.18.51, <= 6.18.* is unaffected.
- Version 7.2.5, <= 7.2.* is unaffected.
- Version 7.3-rc2, <= * is unaffected.