CVE-2026-93272: Linux

EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: remoteproc: qcom_wcnss: Fix handling the lack of PD regulators in v3 The changes introduced to handle single power domain platforms have swapped the info pointer increment from num_pd_vregs to num_pds, which would shift the info pointer past the end of the array for pronto-v3, which does not list power domain regulators in vregs. This showed up as a difference between GCC- and LLVM-compiled kernels on SDM632 devices, where only with LLVM one would get the "regulator request with no identifier" error, because the out-of-bounds memory ended up being zeroed. Fix by skipping the increment when there are more power domains than regulators.

Affected products

  • Linux Linux: from 5.15.185, before 5.16 (fixed in 5.16); from 6.1.141, before 6.2 (fixed in 6.2); from 6.6.93, before 6.7 (fixed in 6.7); from 6.12.31, before 6.13 (fixed in 6.13); from 6.14.9, before 6.15 (fixed in 6.15); from 6.15, before 7.2.6 (fixed in 7.2.6)

Published 2026-09-24. Last modified 2026-09-24.