{"id":"CVE-2026-90122","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nclk: visconti: Make sure clk_init_data is fully initialized\n\nThe clk_init_data structure contains several mutually-exclusive members\nfor different methods to specify th…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nclk: visconti: Make sure clk_init_data is fully initialized\n\nThe clk_init_data structure contains several mutually-exclusive members\nfor different methods to specify th…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= b4cbe606dc3674b25cb661e7cd1a1c6ddaaafaaa < 0e97c22b286e1918c6f48bad7e77fb8240a24b4a","Linux >= b4cbe606dc3674b25cb661e7cd1a1c6ddaaafaaa < 9f756f1965bad65e6066608f33c36988cd10302a","Linux >= b4cbe606dc3674b25cb661e7cd1a1c6ddaaafaaa < 1cc0539e5b0906bace15d3fc7347b344a017cc02","Linux >= b4cbe606dc3674b25cb661e7cd1a1c6ddaaafaaa < 8f7980033e9f7ecaaecd873a0b5bf6b6c87d7e5a","Linux >= b4cbe606dc3674b25cb661e7cd1a1c6ddaaafaaa < 5ecfa72e74c6e2a765fa5bc1da574e5beae588f2","Linux >= b4cbe606dc3674b25cb661e7cd1a1c6ddaaafaaa < 39c0e6c844a14945040cca4ccf6997792ab764c4","Linux 5.17"],"published":"2026-09-17","updated":"2026-09-17","sourceUpdated":"2026-09-17T17:17:04.420","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-90122","references":[{"url":"https://git.kernel.org/stable/c/0e97c22b286e1918c6f48bad7e77fb8240a24b4a","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1cc0539e5b0906bace15d3fc7347b344a017cc02","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/39c0e6c844a14945040cca4ccf6997792ab764c4","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5ecfa72e74c6e2a765fa5bc1da574e5beae588f2","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8f7980033e9f7ecaaecd873a0b5bf6b6c87d7e5a","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9f756f1965bad65e6066608f33c36988cd10302a","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-17T16:21:47.885Z","epss":0.00206,"epssPercentile":0.10944,"slug":"CVE-2026-90122","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nclk: visconti: Make sure clk_init_data is fully initialized\n\nThe clk_init_data structure contains several mutually-exclusive members\nfor different methods to specify the possible parents of a clock,\nprompting drivers to initialize only the members they need.  However,\nnot initializing all members may cause subtle issues, which are only\nexposed when CONFIG_INIT_STACK_ALL_PATTERN or CONFIG_INIT_STACK_NONE is\nenabled.\n\nvisconti_clk_register_gate() fills in init.parent_data, and assumes that\ninit.parent_names is NULL.  However, the latter in uninitialized, and\nthus may cause a crash.\n\nMake sure all members are fully initialized, to fix such bugs, and to\navoid future breakage when converting drivers to a different method for\nspecifying the parents.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}