Answer in brief
CVE-2026-89936 records a Unknown severity vulnerability in iio: dac: m62332: Fix regulator reference count imbalance. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=b87b0c0f81e8d11c881b726b886b7502ab67d884 <bac0ed8bee651aa841375edf72c6ab1d10ac80c6 || >=b87b0c0f81e8d11c881b726b886b7502ab67d884 <9263b9ad968a563337a60e0eb66e35186e1faf9a || >=b87b0c0f81e8d11c881b726b886b7502ab67d884 <1d3a7d7dd3adee19e00be2b2237140f0fe169484 || >=b87b0c0f81e8d11c881b726b886b7502ab67d884 <f5acb824277a97a5210c454872202bf7f08c75d4 || >=b87b0c0f81e8d11c881b726b886b7502ab67d884 <ae18d2d2ef27a4d04fda6e30c23774513dc9be1e || >=b87b0c0f81e8d11c881b726b886b7502ab67d884 <08ac8d2976d57aa943d64e351c4d0bd8bb0c6de9 || >=b87b0c0f81e8d11c881b726b886b7502ab67d884 <9fe22f563b2a0fdb11fd3711a8c39c023629c08a || >=b87b0c0f81e8d11c881b726b886b7502ab67d884 <a130404ce0b69ca1438126bd81c1985d3b4d2e6f | bac0ed8bee651aa841375edf72c6ab1d10ac80c6, 9263b9ad968a563337a60e0eb66e35186e1faf9a, 1d3a7d7dd3adee19e00be2b2237140f0fe169484, f5acb824277a97a5210c454872202bf7f08c75d4, ae18d2d2ef27a4d04fda6e30c23774513dc9be1e, 08ac8d2976d57aa943d64e351c4d0bd8bb0c6de9, 9fe22f563b2a0fdb11fd3711a8c39c023629c08a, a130404ce0b69ca1438126bd81c1985d3b4d2e6f |
| Linux/Linuxgeneric | 4.2 | Not reported |
Published upstream
Sep 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 16, 2026
In the Linux kernel, the following vulnerability has been resolved: iio: dac: m62332: Fix regulator reference count imbalance m62332_set_value() enables the Vcc regulator on every write of a non-zero value and disables it on every write of zero, without tracking the channel's current state. Because the regulator is reference counted, changing a channel directly from one non-zero value to another enables it more than once, while a later write of zero disables it only once. The reference count never returns to zero and the regulator is left enabled indefinitely. Only enable the regulator on the transition from zero to non-zero, and only disable it on the transition from non-zero to zero, using the previously stored channel value to detect the edge. Balance the regulator on the I2C error path so the reference count stays consistent if the write fails.
Quoted source text, attributed separately from HOL analysis.