7.8
CVE-2026-89472
- EPSS 0.16%
- Veröffentlicht 11.09.2026 19:43:30
- Zuletzt bearbeitet 13.09.2026 07:17:10
- Erkennungen
power: supply: charger-manager: register regulators before exposing sysfs
In the Linux kernel, the following vulnerability has been resolved: power: supply: charger-manager: register regulators before exposing sysfs charger_manager_remove() and the err_reg_extcon probe error path free each charger regulator with regulator_put() before tearing down the power_supply sysfs entries (power_supply_unregister()). charger_manager_remove() also calls try_charger_enable(cm, false) after the regulator_put() loop. A concurrent write to a charger's externally_control sysfs attribute that lands between regulator_put() and power_supply_unregister() can run charger_externally_control_store() and call try_charger_enable(), which, when charging is enabled, dereferences the already-freed consumer handle. When charging is enabled, try_charger_enable(cm, false) in .remove() also dereferences the freed handles directly. Both leave use-after-free windows. Symmetrically, probe registers the sysfs entries (power_supply_register) before acquiring the regulators (regulator_get, inside charger_manager_register_extcon), so userspace can reach externally_control before the regulators are available. Split charger_manager_register_extcon() on the sync/async boundary: charger_manager_get_regulators() (regulator_get only, no async producer) now runs before power_supply_register() so sysfs is not live before regulators are available, and charger_manager_register_extcon() keeps only the extcon notifier/work setup, still after power_supply_register() so a power_supply_register() failure cannot reach extcon setup. This keeps the sysfs setup/teardown ordering symmetric without introducing an asynchronous producer on the earlier probe-error path. Move power_supply_unregister() and try_charger_enable(cm, false) ahead of the regulator_put() loop on both teardown paths, and adjust err_reg_extcon (power_supply_unregister() then fall through err_regulator for regulator_put(); get_regulators self-rolls back on its own failure). This does not address the separate extcon-notifier-driven deref of the same handles, which needs its own synchronization design. Found by an in-house static analysis tool.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
3950c7865cd7c963982a2c94457182b96732f4c9
Version <
af3ce383ba0d0d48957a22ac7058ff5698775898
Status
affected
Version
3950c7865cd7c963982a2c94457182b96732f4c9
Version <
86e4fa65368f3bbb506dddba8c9eedc75bd603b2
Status
affected
Version
3950c7865cd7c963982a2c94457182b96732f4c9
Version <
6d532582ff3c420598f02945b13184c738cc1581
Status
affected
Version
3950c7865cd7c963982a2c94457182b96732f4c9
Version <
c57cb36f76eb7ced45f57af1a890d8f3a6d76342
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
3.7
Status
affected
Version
0
Version <
3.7
Status
unaffected
Version <=
6.12.*
Version
6.12.109
Status
unaffected
Version <=
6.18.*
Version
6.18.50
Status
unaffected
Version <=
7.2.*
Version
7.2.4
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.054 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/af3ce383ba0d0d48957a22ac7058ff5698775898
https://git.kernel.org/stable/c/86e4fa65368f3bbb506dddba8c9eedc75bd603b2
https://git.kernel.org/stable/c/6d532582ff3c420598f02945b13184c738cc1581
https://git.kernel.org/stable/c/c57cb36f76eb7ced45f57af1a890d8f3a6d76342