CVE-2026-89585
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
auxdisplay: charlcd: cancel backlight work on registration failure
With CONFIG_CHARLCD_BL_FLASH, charlcd_init() schedules bl_work before charlcd_register() calls misc_register(). If registration fails, the caller frees the charlcd object while delayed work still contains its address.
Add charlcd_deinit() to cancel the delayed work and turn the backlight off. Use it for both registration rollback and normal unregistration.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 39f8ea46724efbed3ca021863a22337c31be264c < fe7ba73dde94c5f413b1588cd444b49105015dda | affected |
| Linux | Linux | 39f8ea46724efbed3ca021863a22337c31be264c < 84858671842ae5857b9ed1202b62f9045373dcd1 | affected |
| Linux | Linux | 39f8ea46724efbed3ca021863a22337c31be264c < ff2fb3c1e60cb247ea3e28c0ea0bea81c18f7755 | affected |
| Linux | Linux | 39f8ea46724efbed3ca021863a22337c31be264c < e3e3bf40916c1e810df03958cfa7ba6883cdce79 | affected |
| Linux | Linux | 4.12 | affected |
| Linux | Linux | 0 < 4.12 | unaffected |
| Linux | Linux | 6.12.109 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.50 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.4 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/fe7ba73dde94c5f413b1588cd444b49105015dda
- https://git.kernel.org/stable/c/84858671842ae5857b9ed1202b62f9045373dcd1
- https://git.kernel.org/stable/c/ff2fb3c1e60cb247ea3e28c0ea0bea81c18f7755
- https://git.kernel.org/stable/c/e3e3bf40916c1e810df03958cfa7ba6883cdce79
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.