Critical Alert 1 Active Exploit Detected Today

CVE-2026-7273 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

← Back to CVE List

CVE-2026-90126NVD

Vulnerability Summary

In the Linux kernel, the following vulnerability has been resolved:

rtc: pcf8563: fix clock provider leak on unbind

pcf8563_clkout_register_clk() registers the CLKOUT clock provider with
of_clk_add_provider(), but nothing ever unwinds it: there is no
of_clk_del_provider() call and the driver has no remove callback. Each
of_clk_add_provider() allocates a struct of_clk_provider, takes a
reference on the OF node and adds an entry to the global of_clk_providers
list, none of which is released when the device is unbound. Every
bind/unbind (or module reload) therefore leaks a provider structure and
an of_node reference.

The clock itself is already device-managed (devm_clk_register()); only
the provider registration was not. Use devm_of_clk_add_hw_provider() so
the provider is removed automatically on unbind. Tie it to the parent
i2c device, whose OF node carries the #clock-cells and clock-output-names
properties (the RTC class device has no OF node of its own).
Severity Level
UNKNOWN
Published Date
Sep 17, 2026
Last Modified
Sep 17, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.21%Probability
Root Weakness (CWE)
N/A

Affected & Patched Versions

Affected Versions
  • Linux Linux >= a39a6405d5f949bc651694028a55d74c514ef1f9 and < 2b5622cf4ee218b6f98d31dbf3fbd44b9b6bd675
  • Linux Linux >= a39a6405d5f949bc651694028a55d74c514ef1f9 and < 36cb00c33bd83e7ce31b5a9f1f7c70db0cb7776c
  • Linux Linux >= a39a6405d5f949bc651694028a55d74c514ef1f9 and < 30b7c63af50fe1464e7582a37de1ca4bd030ecc1
  • Linux Linux >= a39a6405d5f949bc651694028a55d74c514ef1f9 and < 7afb8db47c4f107bce89cfe5115fb31ba7c94665
  • Linux Linux >= a39a6405d5f949bc651694028a55d74c514ef1f9 and < 97edf3fd9a46ea89a167966991c0449cfa07b36f
  • Linux Linux >= a39a6405d5f949bc651694028a55d74c514ef1f9 and < 08a59c28c2bdbcd655e99526c86a41dc83834283
  • Linux Linux >= a39a6405d5f949bc651694028a55d74c514ef1f9 and < 6218c0533a72235ec9c5f41b812c63d963bd4a3e
  • Linux Linux >= a39a6405d5f949bc651694028a55d74c514ef1f9 and < 9c48a53685040bb0de45a640b34055cbbfc69d4f
  • Linux Linux >= 4.4
Patched Versions
  • Linux Linux 2b5622cf4ee218b6f98d31dbf3fbd44b9b6bd675
  • Linux Linux 36cb00c33bd83e7ce31b5a9f1f7c70db0cb7776c
  • Linux Linux 30b7c63af50fe1464e7582a37de1ca4bd030ecc1
  • Linux Linux 7afb8db47c4f107bce89cfe5115fb31ba7c94665
  • Linux Linux 97edf3fd9a46ea89a167966991c0449cfa07b36f
  • Linux Linux 08a59c28c2bdbcd655e99526c86a41dc83834283
  • Linux Linux 6218c0533a72235ec9c5f41b812c63d963bd4a3e
  • Linux Linux 9c48a53685040bb0de45a640b34055cbbfc69d4f
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.