{"id":"CVE-2026-90028","published":"2026-09-16T11:17:15.837","lastModified":"2026-09-16T11:17:15.837","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: hd3ss3220: track VBUS enable state per consumer\n\nregulator_is_enabled() reports the aggregate regulator state, not\nwhether this consumer holds an enable reference. If another consumer\nenables VBUS first, the driver can skip its own regulator_enable() call\nand later attempt to drop a reference it never acquired, triggering an\nunbalanced regulator disable warning.\n\nTrack successful enable and disable calls locally. Keep the state\nunchanged when an operation fails so a later role or ID notification\nretries the operation while this consumer keeps balanced references.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/c9a48db776d7184981630ecc01a3ad30a8f7dc24","tags":[]},{"url":"https://git.kernel.org/stable/c/df7cd3908e07503fa7e9737dacf44208530e58d9","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}