CVE-2026-31741

MEDIUM

counter: rz-mtu3-cnt: prevent counter from being toggled multiple times

Title source: cna
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: counter: rz-mtu3-cnt: prevent counter from being toggled multiple times Runtime PM counter is incremented / decremented each time the sysfs enable file is written to. If user writes 0 to the sysfs enable file multiple times, runtime PM usage count underflows, generating the following message. rz-mtu3-counter rz-mtu3-counter.0: Runtime PM usage count underflow! At the same time, hardware registers end up being accessed with clocks off in rz_mtu3_terminate_counter() to disable an already disabled channel. If user writes 1 to the sysfs enable file multiple times, runtime PM usage count will be incremented each time, requiring the same number of 0 writes to get it back to 0. If user writes 0 to the sysfs enable file while PWM is in progress, PWM is stopped without counter being the owner of the underlying MTU3 channel. Check against the cached count_is_enabled value and exit if the user is trying to set the same enable value.

Scores

CVSS v3 5.5
EPSS 0.0001
EPSS Percentile 2.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (14)
Linux/Linux < 6.4
Linux/Linux 0be8907359df4c62319f5cb2c6981ff0d9ebf35a - 67c3f99bed6f422ba343d2b70a2eeeccdfd91bef
Linux/Linux 0be8907359df4c62319f5cb2c6981ff0d9ebf35a - 885aa739a07ab45e90dfa997205acec97979ce4e
Linux/Linux 0be8907359df4c62319f5cb2c6981ff0d9ebf35a - ced8b48420eddb1251f93c22dc23fa136490b3cd
Linux/Linux 0be8907359df4c62319f5cb2c6981ff0d9ebf35a - e07237df8538b0ae98dce112e4f6db093d767f80
Linux/Linux 0be8907359df4c62319f5cb2c6981ff0d9ebf35a - f5f6f06d7e6d262026578b59ba7426eb04acce5d
Linux/Linux 6.12.81 - 6.12.*
Linux/Linux 6.18.22 - 6.18.*
Linux/Linux 6.19.12 - 6.19.*
Linux/Linux 6.4
... and 4 more
Published May 01, 2026
Tracked Since May 01, 2026