CVE-2026-89465
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
power: supply: rt9455: quiesce delayed work before teardown
The threaded IRQ handler can queue pwr_rdy_work, max_charging_time_work and batt_presence_work. pwr_rdy_work and batt_presence_work can also queue max_charging_time_work, while batt_presence_work can requeue itself.
rt9455_remove() cancels max_charging_time_work before batt_presence_work. The latter can therefore queue max_charging_time_work after it has already been cancelled:
rt9455_remove() workqueue cancel pwr_rdy_work cancel max_charging_time_work batt_presence_work queues max_charging_time_work cancel batt_presence_work return devres frees rt9455_info max_charging_time_work dereferences rt9455_info
The IRQ also remains registered until devres cleanup and can queue more work after any of the cancellation calls. If rt9455_hw_init() fails after the IRQ has been requested, probe returns without cancelling work that may already have been queued. A pending callback can then access rt9455_info after it has been freed.
Register rt9455_cancel_all_delayed_works() through devm_add_action_or_reset() right after devm_power_supply_register(). devres invokes the action in reverse registration order, after the managed IRQ has been freed and before rt9455_info is released, so the delayed works are drained in both rt9455_remove() and the probe error path. Cancel pwr_rdy_work and batt_presence_work before max_charging_time_work because both can queue the latter.
This issue was found by an in-house static analysis tool.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | e86d69dd786e94046b8f5be7df1b9a8226a40b2a < df67c7a2fff8414aa766b8cd5ffe11ec1ca27d02 | affected |
| Linux | Linux | e86d69dd786e94046b8f5be7df1b9a8226a40b2a < 1b9978433c61a9b46e48832a1ebceee1cf5c9eb4 | affected |
| Linux | Linux | e86d69dd786e94046b8f5be7df1b9a8226a40b2a < 7323e562f6961e4b7bce3225cde4ecbc78260deb | affected |
| Linux | Linux | e86d69dd786e94046b8f5be7df1b9a8226a40b2a < 3e7a1ebc32fad5a558254a478efd401c17a24381 | affected |
| Linux | Linux | 4.2 | affected |
| Linux | Linux | 0 < 4.2 | unaffected |
| Linux | Linux | 6.12.109 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.50 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.4 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/df67c7a2fff8414aa766b8cd5ffe11ec1ca27d02
- https://git.kernel.org/stable/c/1b9978433c61a9b46e48832a1ebceee1cf5c9eb4
- https://git.kernel.org/stable/c/7323e562f6961e4b7bce3225cde4ecbc78260deb
- https://git.kernel.org/stable/c/3e7a1ebc32fad5a558254a478efd401c17a24381
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.