{"id":"CVE-2026-90360","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nregulator: core: use system_freezable_wq for init complete work\n\nschedule_delayed_work() uses system_wq, which is non-freezable, allowing\nregulator_init_complete_work t…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nregulator: core: use system_freezable_wq for init complete work\n\nschedule_delayed_work() uses system_wq, which is non-freezable, allowing\nregulator_init_complete_work t…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 8b8c8d69b1a31004517d4c71a490f47bdf3405a2 < 8a2ae3ab348cce44120667277c2198f10cc348b1","Linux >= d7ce17fba6c8e316ca9a554a87edddce6f862435 < 350a0cba90e1bd40b1fe5b396923d2f3a61d1056","Linux >= 55576cf1853798e86f620766e23b604c9224c19c < 2cebc00340a585adeffe321bc41f1937eb79a4dc","Linux >= 55576cf1853798e86f620766e23b604c9224c19c < 9cf65270c1c1717c84dcfacd58a782c1186b0cbf","Linux >= 55576cf1853798e86f620766e23b604c9224c19c < dc8570a5b830190bf0b57017c35aef97cd6ad7d9","Linux >= 55576cf1853798e86f620766e23b604c9224c19c < 6d0a2c5e210f2fba099129e6183ef81316a6ae48","Linux >= 55576cf1853798e86f620766e23b604c9224c19c < 0d23d658d79925076026fff62a49b8c94e0e8922","Linux >= 55576cf1853798e86f620766e23b604c9224c19c < 0b950aa7ec95e120b2bde745ca9a7ed3ce49d528","Linux >= 55576cf1853798e86f620766e23b604c9224c19c < 29dc2e24f6adb36dcb884acf455644c397a67471","Linux >= 55576cf1853798e86f620766e23b604c9224c19c < 03eab318cedd6ae34ecd34533cd986edf5237164","Linux c4f65c2fb0f5c488d4ae606fba94bb98dcf383fd","Linux d6acb54716ffab29f15c66082bd751410b284764","Linux 3fbfa415a5dd8fc78076c1ead160a03a058cd9f6","Linux >= 4.9.195 < 4.9.207","Linux >= 4.14.147 < 4.14.160","Linux >= 4.19.77 < 4.20","Linux >= 5.2.19 < 5.3","Linux >= 5.3.4 < 5.4","Linux 5.4"],"published":"2026-09-17","updated":"2026-09-17","sourceUpdated":"2026-09-17T17:17:34.913","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-90360","references":[{"url":"https://git.kernel.org/stable/c/03eab318cedd6ae34ecd34533cd986edf5237164","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0b950aa7ec95e120b2bde745ca9a7ed3ce49d528","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0d23d658d79925076026fff62a49b8c94e0e8922","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/29dc2e24f6adb36dcb884acf455644c397a67471","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2cebc00340a585adeffe321bc41f1937eb79a4dc","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/350a0cba90e1bd40b1fe5b396923d2f3a61d1056","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6d0a2c5e210f2fba099129e6183ef81316a6ae48","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8a2ae3ab348cce44120667277c2198f10cc348b1","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9cf65270c1c1717c84dcfacd58a782c1186b0cbf","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dc8570a5b830190bf0b57017c35aef97cd6ad7d9","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-17T16:21:47.812Z","epss":0.00239,"epssPercentile":0.15236,"slug":"CVE-2026-90360","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nregulator: core: use system_freezable_wq for init complete work\n\nschedule_delayed_work() uses system_wq, which is non-freezable, allowing\nregulator_init_complete_work to run concurrently with system suspend. This\nwork fires ~30s after boot to disable unused regulators via I2C. When it\nraces with PM suspend, the I2C adapter may already be suspended, triggering\na -ESHUTDOWN warning in __i2c_transfer():\n\n  WARNING: ... at __i2c_transfer+0x36c/0x3c8\n  Call trace:\n   __i2c_transfer\n   i2c_transfer\n   regmap_i2c_write\n   _regmap_update_bits\n   regulator_disable_regmap\n   _regulator_do_disable\n   regulator_late_cleanup\n   regulator_init_complete_work_function\n   process_one_work\n\nSwitch to system_freezable_wq so the work is frozen before any device\nis suspended, eliminating the race.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}