---
id: CVE-2026-93263
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  clk: eswin: Zero-initialize stack-allocated clk_init_data

  eswin_clk_register_pll() and eswin_register_clkdiv() declare a struct
  clk_init_data on the stack and only ini…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  clk: eswin: Zero-initialize stack-allocated clk_init_data

  eswin_clk_register_pll() and eswin_register_clkdiv() declare a struct
  clk_init_data on the stack and only ini…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= cd44f127c1d42833a32ba0a0965255ee6184f8c1 <
    1183dc2450a268a536a15da8b106ec520cdbd19f
  - >-
    Linux >= cd44f127c1d42833a32ba0a0965255ee6184f8c1 <
    011d8de504bc84402aabc1dda1cf0552fe9a5af2
  - Linux 7.1
published: '2026-09-24'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T16:17:23.067'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93263'
references:
  - url: 'https://git.kernel.org/stable/c/011d8de504bc84402aabc1dda1cf0552fe9a5af2'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/1183dc2450a268a536a15da8b106ec520cdbd19f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-24T16:47:15.836Z'
epss: 0.00176
epssPercentile: 0.06408
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

clk: eswin: Zero-initialize stack-allocated clk_init_data

eswin_clk_register_pll() and eswin_register_clkdiv() declare a struct
clk_init_data on the stack and only initialize some of its fields
(parent_data respectively parent_hws). clk_core_populate_parent_map()
checks parent_names first and parent_data second before falling back
to parent_hws, so leftover stack garbage in the uninitialized fields
hijacks parent resolution and the clk core dereferences a bogus
pointer:

  Unable to handle kernel NULL pointer dereference at virtual address 000000000000000c
  Oops [#1]
  epc : __clk_register+0x31a/0x7f0
  [<ffffffff805dc774>] __clk_register+0x31a/0x7f0
  [<ffffffff805dcd76>] devm_clk_hw_register+0x2a/0x94
  [<ffffffff805e319a>] eswin_register_clkdiv+0x80/0xd0
  [<ffffffff805e34a0>] eswin_clk_register_clks+0x162/0x1a0
  [<ffffffff805e3736>] eic7700_clk_probe+0x146/0x180
  [<ffffffff8065d23c>] platform_probe+0x3c/0x7a

Observed on EIC7700 hardware (with the driver backported to a 6.17
tree); whether the bug triggers depends entirely on what the stack
happens to contain when the registration helpers run.

Zero-initialize both structures.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
