{"id":"CVE-2026-89936","title":"In the Linux kernel, the following vulnerability has been resolved:\n\niio: dac: m62332: Fix regulator reference count imbalance\n\nm62332_set_value() enables the Vcc regulator on every write of a\nnon-zero value and disables it on every writ…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\niio: dac: m62332: Fix regulator reference count imbalance\n\nm62332_set_value() enables the Vcc regulator on every write of a\nnon-zero value and disables it on every writ…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= b87b0c0f81e8d11c881b726b886b7502ab67d884 < bac0ed8bee651aa841375edf72c6ab1d10ac80c6","Linux >= b87b0c0f81e8d11c881b726b886b7502ab67d884 < 9263b9ad968a563337a60e0eb66e35186e1faf9a","Linux >= b87b0c0f81e8d11c881b726b886b7502ab67d884 < 1d3a7d7dd3adee19e00be2b2237140f0fe169484","Linux >= b87b0c0f81e8d11c881b726b886b7502ab67d884 < f5acb824277a97a5210c454872202bf7f08c75d4","Linux >= b87b0c0f81e8d11c881b726b886b7502ab67d884 < ae18d2d2ef27a4d04fda6e30c23774513dc9be1e","Linux >= b87b0c0f81e8d11c881b726b886b7502ab67d884 < 08ac8d2976d57aa943d64e351c4d0bd8bb0c6de9","Linux >= b87b0c0f81e8d11c881b726b886b7502ab67d884 < 9fe22f563b2a0fdb11fd3711a8c39c023629c08a","Linux >= b87b0c0f81e8d11c881b726b886b7502ab67d884 < a130404ce0b69ca1438126bd81c1985d3b4d2e6f","Linux 4.2"],"published":"2026-09-16","updated":"2026-09-16","sourceUpdated":"2026-09-16T11:17:03.027","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-89936","references":[{"url":"https://git.kernel.org/stable/c/08ac8d2976d57aa943d64e351c4d0bd8bb0c6de9","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1d3a7d7dd3adee19e00be2b2237140f0fe169484","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9263b9ad968a563337a60e0eb66e35186e1faf9a","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9fe22f563b2a0fdb11fd3711a8c39c023629c08a","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a130404ce0b69ca1438126bd81c1985d3b4d2e6f","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ae18d2d2ef27a4d04fda6e30c23774513dc9be1e","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bac0ed8bee651aa841375edf72c6ab1d10ac80c6","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f5acb824277a97a5210c454872202bf7f08c75d4","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-16T10:53:53.967Z","epss":0.00211,"epssPercentile":0.11601,"slug":"CVE-2026-89936","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\niio: dac: m62332: Fix regulator reference count imbalance\n\nm62332_set_value() enables the Vcc regulator on every write of a\nnon-zero value and disables it on every write of zero, without tracking\nthe channel's current state. Because the regulator is reference counted,\nchanging a channel directly from one non-zero value to another enables\nit more than once, while a later write of zero disables it only once.\nThe reference count never returns to zero and the regulator is left\nenabled indefinitely.\n\nOnly enable the regulator on the transition from zero to non-zero, and\nonly disable it on the transition from non-zero to zero, using the\npreviously stored channel value to detect the edge. Balance the\nregulator on the I2C error path so the reference count stays consistent\nif the write fails.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}