CVE-2026-90394

Summary

In the Linux kernel, the following vulnerability has been resolved:

power: supply: sc2731_charger: cancel work on remove

The USB notifier and initial charger detection can schedule info->work. The remove path unregisters the notifier, but does not cancel queued or running work before the devm-allocated driver data is released.

Set the platform drvdata used by remove, then cancel the work after unregistering the notifier.

This issue was found by a static analysis tool.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux8ac1091ed18b4a6cb0dc2cd5653f080736f89392 < bb74a5ab30963022981381ea6aee176fd0c7957caffected
LinuxLinux8ac1091ed18b4a6cb0dc2cd5653f080736f89392 < 232e9e946b496e4706e2f34ce4a617460d8ae713affected
LinuxLinux8ac1091ed18b4a6cb0dc2cd5653f080736f89392 < 05c188addc6d1af51e28496e95096f4df9a000e9affected
LinuxLinux8ac1091ed18b4a6cb0dc2cd5653f080736f89392 < 972d88069050d0272b776145b824198b8f899dceaffected
LinuxLinux8ac1091ed18b4a6cb0dc2cd5653f080736f89392 < c6df6e0c099086bc553d44410015cc81795070e6affected
LinuxLinux8ac1091ed18b4a6cb0dc2cd5653f080736f89392 < d5266b4c5c77152e386a3a2d9d5244b3b6cbd57aaffected
LinuxLinux8ac1091ed18b4a6cb0dc2cd5653f080736f89392 < aab9d81a415c6653b44b057695ebfbba34dc9556affected
LinuxLinux8ac1091ed18b4a6cb0dc2cd5653f080736f89392 < dfc859bb8d332c525872f1a44028137724fa1998affected
LinuxLinux5.0affected
LinuxLinux0 < 5.0unaffected
LinuxLinux5.10.270 <= 5.10.*unaffected
LinuxLinux5.15.221 <= 5.15.*unaffected
LinuxLinux6.1.188 <= 6.1.*unaffected
LinuxLinux6.6.157 <= 6.6.*unaffected
LinuxLinux6.12.110 <= 6.12.*unaffected
LinuxLinux6.18.52 <= 6.18.*unaffected
LinuxLinux7.2.6 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References