---
id: CVE-2026-98001
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  hwmon: (ltc4282) Make sure clk_init_data is fully initialized

  The clk_init_data structure contains several mutually-exclusive members
  for different methods to specify …
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  hwmon: (ltc4282) Make sure clk_init_data is fully initialized

  The clk_init_data structure contains several mutually-exclusive members
  for different methods to specify …
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= cbc29538dbf7d7400f1ffc5dd5713e6a551463a0 <
    c4a96da5a3f132d80aa971ddbeb86808539ba0e6
  - >-
    Linux >= cbc29538dbf7d7400f1ffc5dd5713e6a551463a0 <
    80b46a3d066d4e2c1dd4edb90d4aa3f22ca79f39
  - >-
    Linux >= cbc29538dbf7d7400f1ffc5dd5713e6a551463a0 <
    aa08ce1ffaf36c7bdd3edd0ad65f72413639bfad
  - >-
    Linux >= cbc29538dbf7d7400f1ffc5dd5713e6a551463a0 <
    e317326d1755ea054b98e7a4833b929157461c35
  - Linux 6.9
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T11:17:28.320'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98001'
references:
  - url: 'https://git.kernel.org/stable/c/80b46a3d066d4e2c1dd4edb90d4aa3f22ca79f39'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/aa08ce1ffaf36c7bdd3edd0ad65f72413639bfad'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/c4a96da5a3f132d80aa971ddbeb86808539ba0e6'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e317326d1755ea054b98e7a4833b929157461c35'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-25T11:06:38.862Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

hwmon: (ltc4282) Make sure clk_init_data is fully initialized

The clk_init_data structure contains several mutually-exclusive members
for different methods to specify the possible parents of a clock,
prompting drivers to initialize only the members they need.  However,
not initializing all members may cause subtle issues, which are only
exposed when CONFIG_INIT_STACK_ALL_PATTERN or CONFIG_INIT_STACK_NONE is
enabled.

ltc428_clk_provider_setup() does not fill in any parent clocks, and
assumes that init.num_parents is NULL.  However, the latter in
uninitialized, and thus may cause a crash.

Make sure all members are fully initialized, to fix such bugs, and to
avoid future breakage when converting drivers to a different method for
specifying the parents.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
