-

CVE-2026-89463

power: supply: ucs1002: fix use-after-free on remove

In the Linux kernel, the following vulnerability has been resolved:

power: supply: ucs1002: fix use-after-free on remove

ucs1002 has no remove callback, so unbind runs entirely through devm.
The alert IRQ handler queues the health_poll delayed work, and the work
reschedules itself while the chip reports a bad-health condition.  devm
frees the alert IRQ, which only synchronizes the handler; it does not
cancel the delayed work, which can then run after devm frees the driver
data and dereference it.

Register health_poll with devm_delayed_work_autocancel() before the
alert IRQ is requested.  devm then frees the IRQ before cancelling the
work, so the handler can no longer queue it and the work is cancelled
before the driver data is freed.

This issue was found by an in-house static analysis tool.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 81196e2e57fc5b88f6b8ca98372a3dde047aa49d
Version < 00c19f8a9a58a318a76fd6f735a8aab3f8ead393
Status affected
Version 81196e2e57fc5b88f6b8ca98372a3dde047aa49d
Version < a9a7bb801c443a4d9fc623c4a47deb53accb70bb
Status affected
Version 81196e2e57fc5b88f6b8ca98372a3dde047aa49d
Version < 2ec4d203ecb06d327af67e32097fe8f774838a40
Status affected
Version 81196e2e57fc5b88f6b8ca98372a3dde047aa49d
Version < 4ca2a4678202f15eb790eb7f1d562061709caea7
Status affected
Version 81196e2e57fc5b88f6b8ca98372a3dde047aa49d
Version < 39b60d615dfa1725c235351fb12bc72e5f8a8d32
Status affected
Version 81196e2e57fc5b88f6b8ca98372a3dde047aa49d
Version < 35242c93d35f391afdc84cef6236b8ad57f1df24
Status affected
Version 81196e2e57fc5b88f6b8ca98372a3dde047aa49d
Version < 609af0ceeaefdfa42cd01dd060b20f2e41f9a232
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.10
Status affected
Version 0
Version < 5.10
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.1
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/4ca2a4678202f15eb790eb7f1d562061709caea7
https://git.kernel.org/stable/c/39b60d615dfa1725c235351fb12bc72e5f8a8d32
https://git.kernel.org/stable/c/35242c93d35f391afdc84cef6236b8ad57f1df24
https://git.kernel.org/stable/c/609af0ceeaefdfa42cd01dd060b20f2e41f9a232
https://git.kernel.org/stable/c/00c19f8a9a58a318a76fd6f735a8aab3f8ead393
https://git.kernel.org/stable/c/2ec4d203ecb06d327af67e32097fe8f774838a40
https://git.kernel.org/stable/c/a9a7bb801c443a4d9fc623c4a47deb53accb70bb