Answer in brief
CVE-2026-93272 records a Unknown severity vulnerability in remoteproc: qcom_wcnss: Fix handling the lack of PD regulators in v3. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=65991ea8a6d1e68effdc01d95ebe39f1653f7b71 <bce6b48af3abf7468d12ef4933f21bd8c1d822e9 || >=65991ea8a6d1e68effdc01d95ebe39f1653f7b71 <3dbc90b9c22ea96e37bf55f6011e63b5123ec668 || 654c295f9079d2c7875172142022168e34c4e34e || 8d0d4c11cace475f1b07f98ee3d2bd334590e17b || fef1e1487dea81c2b4560e393ba4b0be57e28d01 || 69bb5b3ae348040e385113efba5bdc76396644d0 || 04a89c98810d2dba8187120c07fdb732aa40ca14 || >=5.15.185 <5.16 || >=6.1.141 <6.2 || >=6.6.93 <6.7 || >=6.12.31 <6.13 || >=6.14.9 <6.15 | bce6b48af3abf7468d12ef4933f21bd8c1d822e9, 3dbc90b9c22ea96e37bf55f6011e63b5123ec668, 5.16, 6.2, 6.7, 6.13, 6.15 |
| Linux/Linuxgeneric | 6.15 | Not reported |
Published upstream
Sep 24, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 24, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 25, 2026
In the Linux kernel, the following vulnerability has been resolved: remoteproc: qcom_wcnss: Fix handling the lack of PD regulators in v3 The changes introduced to handle single power domain platforms have swapped the info pointer increment from num_pd_vregs to num_pds, which would shift the info pointer past the end of the array for pronto-v3, which does not list power domain regulators in vregs. This showed up as a difference between GCC- and LLVM-compiled kernels on SDM632 devices, where only with LLVM one would get the "regulator request with no identifier" error, because the out-of-bounds memory ended up being zeroed. Fix by skipping the increment when there are more power domains than regulators.
Quoted source text, attributed separately from HOL analysis.