CVE-2026-90026

Summary

In the Linux kernel, the following vulnerability has been resolved:

usb: typec: qcom-pmic: cancel reset_work on stop

pdphy_stop() disables IRQs but leaves reset_work pending. If the IRQ handler schedules it just before disable_irq(), the work runs after remove() frees the struct via devm.

Call cancel_work_sync() after disabling IRQs to close the window.

This issue was found by an in-house static analysis tool.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxa4422ff221429c600c3dc5d0394fb3738b89d040 < 0b69b166852dbf1f9532b22bd49f502e5970eb95affected
LinuxLinuxa4422ff221429c600c3dc5d0394fb3738b89d040 < b9a7eed472edbfa8dec0fdeafd5e796550a8a8b7affected
LinuxLinuxa4422ff221429c600c3dc5d0394fb3738b89d040 < d4e00a1eb39174e25ef759b8fb1111bba8e87b1eaffected
LinuxLinuxa4422ff221429c600c3dc5d0394fb3738b89d040 < 52d556f08547733948cc40b8b11e6b68dccee7b2affected
LinuxLinuxa4422ff221429c600c3dc5d0394fb3738b89d040 < 7b0df6efd143f8085bdb68778a013a46f1349913affected
LinuxLinux6.5affected
LinuxLinux0 < 6.5unaffected
LinuxLinux6.6.157 <= 6.6.*unaffected
LinuxLinux6.12.110 <= 6.12.*unaffected
LinuxLinux6.18.51 <= 6.18.*unaffected
LinuxLinux7.2.5 <= 7.2.*unaffected
LinuxLinux7.3-rc2 <= *unaffected

Weaknesses

References