7.8

CVE-2026-89472

power: supply: charger-manager: register regulators before exposing sysfs

In the Linux kernel, the following vulnerability has been resolved:

power: supply: charger-manager: register regulators before exposing sysfs

charger_manager_remove() and the err_reg_extcon probe error path free each
charger regulator with regulator_put() before tearing down the power_supply
sysfs entries (power_supply_unregister()). charger_manager_remove() also
calls try_charger_enable(cm, false) after the regulator_put() loop. A
concurrent write to a charger's externally_control sysfs attribute that
lands between regulator_put() and power_supply_unregister() can run
charger_externally_control_store() and call try_charger_enable(), which,
when charging is enabled, dereferences the already-freed consumer handle.
When charging is enabled, try_charger_enable(cm, false) in .remove() also
dereferences the freed handles directly. Both leave use-after-free windows.
Symmetrically, probe registers the sysfs entries (power_supply_register)
before acquiring the regulators (regulator_get, inside
charger_manager_register_extcon), so userspace can reach externally_control
before the regulators are available.

Split charger_manager_register_extcon() on the sync/async boundary:
charger_manager_get_regulators() (regulator_get only, no async producer)
now runs before power_supply_register() so sysfs is not live before
regulators are available, and charger_manager_register_extcon() keeps only
the extcon notifier/work setup, still after power_supply_register() so a
power_supply_register() failure cannot reach extcon setup. This keeps the
sysfs setup/teardown ordering symmetric without introducing an asynchronous
producer on the earlier probe-error path.

Move power_supply_unregister() and try_charger_enable(cm, false) ahead of
the regulator_put() loop on both teardown paths, and adjust err_reg_extcon
(power_supply_unregister() then fall through err_regulator for
regulator_put(); get_regulators self-rolls back on its own failure).

This does not address the separate extcon-notifier-driven deref of the same
handles, which needs its own synchronization design.

Found by an in-house static analysis tool.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 3950c7865cd7c963982a2c94457182b96732f4c9
Version < af3ce383ba0d0d48957a22ac7058ff5698775898
Status affected
Version 3950c7865cd7c963982a2c94457182b96732f4c9
Version < 86e4fa65368f3bbb506dddba8c9eedc75bd603b2
Status affected
Version 3950c7865cd7c963982a2c94457182b96732f4c9
Version < 6d532582ff3c420598f02945b13184c738cc1581
Status affected
Version 3950c7865cd7c963982a2c94457182b96732f4c9
Version < c57cb36f76eb7ced45f57af1a890d8f3a6d76342
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.7
Status affected
Version 0
Version < 3.7
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.054
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/af3ce383ba0d0d48957a22ac7058ff5698775898
https://git.kernel.org/stable/c/86e4fa65368f3bbb506dddba8c9eedc75bd603b2
https://git.kernel.org/stable/c/6d532582ff3c420598f02945b13184c738cc1581
https://git.kernel.org/stable/c/c57cb36f76eb7ced45f57af1a890d8f3a6d76342