CVE-2026-64230: regulator: tps65219: fix irq_data.rdev not being assigned
Greg Kroah-Hartman <[email protected]> Fri, 24 Jul 2026 17:23:33 +0200
| Newsgroups | org.kernel.vger.linux-cve-announce |
|---|---|
| Message-ID | <2026072418-CVE-2026-64230-3011@gregkh> |
From: Greg Kroah-Hartman <[email protected]> Description =========== In the Linux kernel, the following vulnerability has been resolved: regulator: tps65219: fix irq_data.rdev not being assigned Commit 64a6b577490c ("regulator: tps65219: Remove debugging helper function") removed the tps65219_get_rdev_by_name() helper along with the irq_data.rdev assignment that depended on it. This left irq_data.rdev uninitialized for all IRQs, causing undefined behavior when regulator_notifier_call_chain() is called from the IRQ handler: Internal error: Oops: 0000000096000004 pc : regulator_notifier_call_chain lr : tps65219_regulator_irq_handler Call trace: regulator_notifier_call_chain tps65219_regulator_irq_handler handle_nested_irq regmap_irq_thread irq_thread_fn irq_thread kthread ret_from_fork Instead of restoring a dedicated lookup array, restructure the probe function to combine regulator registration with IRQ registration in the same loop. This way the rdev returned by devm_regulator_register() is naturally available for assigning to irq_data.rdev without any auxiliary data structure. Non-regulator IRQs (SENSOR, TIMEOUT) that don't correspond to any registered regulator are registered with rdev=NULL, and the IRQ handler is protected with a NULL check to avoid crashing. The Linux kernel CVE team has assigned CVE-2026-64230 to this issue. Affected and fixed versions =========================== Issue introduced in 6.14 with commit 64a6b577490c1c71f1a3bbdb3844717815214621 and fixed in 6.18.34 with commit 6827647fd2dcf4e7f355478a42e82f51e0b5344c Issue introduced in 6.14 with commit 64a6b577490c1c71f1a3bbdb3844717815214621 and fixed in 7.0.11 with commit b986f88b22a5374191c195c073350bbeb1bb6518 Issue introduced in 6.14 with commit 64a6b577490c1c71f1a3bbdb3844717815214621 and fixed in 7.1 with commit f9b2d3b703d13df50c630997dfdc25648e96db0d Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-64230 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/regulator/tps65219-regulator.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/6827647fd2dcf4e7f355478a42e82f51e0b5344c https://git.kernel.org/stable/c/b986f88b22a5374191c195c073350bbeb1bb6518 https://git.kernel.org/stable/c/f9b2d3b703d13df50c630997dfdc25648e96db0d