-

CVE-2026-93263

clk: eswin: Zero-initialize stack-allocated clk_init_data

In the Linux kernel, the following vulnerability has been resolved:

clk: eswin: Zero-initialize stack-allocated clk_init_data

eswin_clk_register_pll() and eswin_register_clkdiv() declare a struct
clk_init_data on the stack and only initialize some of its fields
(parent_data respectively parent_hws). clk_core_populate_parent_map()
checks parent_names first and parent_data second before falling back
to parent_hws, so leftover stack garbage in the uninitialized fields
hijacks parent resolution and the clk core dereferences a bogus
pointer:

  Unable to handle kernel NULL pointer dereference at virtual address 000000000000000c
  Oops [#1]
  epc : __clk_register+0x31a/0x7f0
  [<ffffffff805dc774>] __clk_register+0x31a/0x7f0
  [<ffffffff805dcd76>] devm_clk_hw_register+0x2a/0x94
  [<ffffffff805e319a>] eswin_register_clkdiv+0x80/0xd0
  [<ffffffff805e34a0>] eswin_clk_register_clks+0x162/0x1a0
  [<ffffffff805e3736>] eic7700_clk_probe+0x146/0x180
  [<ffffffff8065d23c>] platform_probe+0x3c/0x7a

Observed on EIC7700 hardware (with the driver backported to a 6.17
tree); whether the bug triggers depends entirely on what the stack
happens to contain when the registration helpers run.

Zero-initialize both structures.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version cd44f127c1d42833a32ba0a0965255ee6184f8c1
Version < 1183dc2450a268a536a15da8b106ec520cdbd19f
Status affected
Version cd44f127c1d42833a32ba0a0965255ee6184f8c1
Version < 011d8de504bc84402aabc1dda1cf0552fe9a5af2
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 7.1
Status affected
Version 0
Version < 7.1
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.064
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/1183dc2450a268a536a15da8b106ec520cdbd19f
https://git.kernel.org/stable/c/011d8de504bc84402aabc1dda1cf0552fe9a5af2