CVE-2026-90027
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: typec: qcom-pmic-typec: disable cc_debounce_dwork on stop
cc_debounce_dwork is queued from the set_cc() and start_toggling() callbacks, which run from TCPM's kthread worker. port_stop() returns before tcpm_unregister_port() destroys that worker. Flushing the worker during unregister may therefore run a callback which queues the delayed work after port_stop() has returned.
The delayed work can then run after devres has freed pmic_typec_port.
Use disable_delayed_work_sync() in port_stop() to cancel a pending instance and prevent the TCPM callbacks from queueing another one.
This issue was found by an in-house static analysis tool.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | a4422ff221429c600c3dc5d0394fb3738b89d040 < 4359b5f95c93a4658e08368fa6fab9d89eb98447 | affected |
| Linux | Linux | a4422ff221429c600c3dc5d0394fb3738b89d040 < c614d7c44ca7fb78867ba46b233acdb59287e8c8 | affected |
| Linux | Linux | a4422ff221429c600c3dc5d0394fb3738b89d040 < 1ab669c2b44e1040ddfab7cd7f717aad580d17aa | affected |
| Linux | Linux | a4422ff221429c600c3dc5d0394fb3738b89d040 < 263f7d61a4201cde16849b2d016251806e7418be | affected |
| Linux | Linux | 6.5 | affected |
| Linux | Linux | 0 < 6.5 | unaffected |
| Linux | Linux | 6.12.110 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.51 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.5 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc2 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/4359b5f95c93a4658e08368fa6fab9d89eb98447
- https://git.kernel.org/stable/c/c614d7c44ca7fb78867ba46b233acdb59287e8c8
- https://git.kernel.org/stable/c/1ab669c2b44e1040ddfab7cd7f717aad580d17aa
- https://git.kernel.org/stable/c/263f7d61a4201cde16849b2d016251806e7418be
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.