OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-93225

HIGH · CVSS 7.4 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's handling of the type-C switch during probe failures in the fsl-imx8mq-usb driver, leading to resource leaks if the initialization process encounters an error. This can result in potential instability or resource exhaustion in systems utilizing this driver. Organizations using affected Linux distributions should prioritize addressing this issue to ensure system reliability and prevent potential exploitation.

CVE
CVE-2026-93225
Severity
HIGH
CVSS
7.4
EPSS
0.14%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: phy: fsl-imx8mq-usb: fix typec switch leak on probe error path If probe fails after imx95_usb_phy_get_tca() succeeds, the typec switch leaks because the only cleanup path was in .remove(), which never runs on probe failure. Use devm_add_action_or_reset() so the switch is cleaned up on both probe failure and driver removal. The imx95_usb_phy_put_tca() is no longer needed, it will be removed in .remove() too.