Answer in brief
CVE-2026-90362 records a Unknown severity vulnerability in drm/msm/dsi: Drop dev_pm_opp_set_rate(0). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=32d3e0feccfe2d07e73aaa322766ab04b3c9d594 <bc1df05cccdb4f08aa42e736b54d265c6c11a45b || >=32d3e0feccfe2d07e73aaa322766ab04b3c9d594 <27e181c185194baf5c1ef18bbff1fc3bc283ef21 || >=32d3e0feccfe2d07e73aaa322766ab04b3c9d594 <5c3e537db05021c93ea40a46bd0c50eee2f30f87 || >=32d3e0feccfe2d07e73aaa322766ab04b3c9d594 <d3e8355a63cead3dedaa52f46cd1ee9796fdc7a8 || >=32d3e0feccfe2d07e73aaa322766ab04b3c9d594 <393b43cc12c95f3d2762a06f799807313029032e || >=32d3e0feccfe2d07e73aaa322766ab04b3c9d594 <83bc4eab83ae5ab88d410148a2e73e09e6f21c04 || >=32d3e0feccfe2d07e73aaa322766ab04b3c9d594 <00008e6f544c2d480f920ab1e593a46cfb87cead || >=32d3e0feccfe2d07e73aaa322766ab04b3c9d594 <06b7ba206561619bb34116f49e0ef26b867ce3aa | bc1df05cccdb4f08aa42e736b54d265c6c11a45b, 27e181c185194baf5c1ef18bbff1fc3bc283ef21, 5c3e537db05021c93ea40a46bd0c50eee2f30f87, d3e8355a63cead3dedaa52f46cd1ee9796fdc7a8, 393b43cc12c95f3d2762a06f799807313029032e, 83bc4eab83ae5ab88d410148a2e73e09e6f21c04, 00008e6f544c2d480f920ab1e593a46cfb87cead, 06b7ba206561619bb34116f49e0ef26b867ce3aa |
| Linux/Linuxgeneric | 5.9 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: drm/msm/dsi: Drop dev_pm_opp_set_rate(0) dev_pm_opp_set_rate(0) removes the vote specified in required-opps but does not actually park the clock, making it run without the necessary power backing. Drop the explicit call to it. Every call site of ops->link_clk_disable() is followed by pm_runtime_put(), so the power vote will be rescinded if deemed safe. Patchwork: https://patchwork.freedesktop.org/patch/742783/
Quoted source text, attributed separately from HOL analysis.