CVE-2026-89463: fallo en Linux
power: supply: ucs1002: fix use-after-free on remove
Publicada el · Actualizada el
3Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackepss 0.2%
probabilidad de explotación
0.2%top 90% de las CVE
explotación observada
noninguna fuente lo reporta
In the Linux kernel, the following vulnerability has been resolved:
power: supply: ucs1002: fix use-after-free on remove
ucs1002 has no remove callback, so unbind runs entirely through devm.
The alert IRQ handler queues the health_poll delayed work, and the work
reschedules itself while the chip reports a bad-health condition. devm
frees the alert IRQ, which only synchronizes the handler; it does not
cancel the delayed work, which can then run after devm frees the driver
data and dereference it.
Register health_poll with devm_delayed_work_autocancel() before the
alert IRQ is requested. devm then frees the IRQ before cancelling the
work, so the handler can no longer queue it and the work is cancelled
before the driver data is freed.
This issue was found by an in-house static analysis tool.
Productos afectados
Linux · LinuxCVEs relacionadas — Linux
En el mismo producto, de las más peligrosas a las menos.
CVE-2024-53197HIGHALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devicesEPSS 4.1%KEVCVE-2026-31431HIGHcrypto: algif_aead - Revert to operating out-of-placeEPSS 3.4%KEVCVE-2024-53104HIGHmedia: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_formatEPSS 3.4%KEVCVE-2025-39682CRITICALtls: fix handling of zero-length records on the rx_listEPSS 2.9%KEVCVE-2024-36971HIGHnet: fix __dst_negative_advice() raceEPSS 2.7%KEVCVE-2024-53150HIGHALSA: usb-audio: Fix out of bounds reads when finding clock sourcesEPSS 1.4%KEV
Referencias
https://git.kernel.org/stable/c/00c19f8a9a58a318a76fd6f735a8aab3f8ead393https://git.kernel.org/stable/c/2ec4d203ecb06d327af67e32097fe8f774838a40https://git.kernel.org/stable/c/35242c93d35f391afdc84cef6236b8ad57f1df24https://git.kernel.org/stable/c/39b60d615dfa1725c235351fb12bc72e5f8a8d32https://git.kernel.org/stable/c/4ca2a4678202f15eb790eb7f1d562061709caea7https://git.kernel.org/stable/c/609af0ceeaefdfa42cd01dd060b20f2e41f9a232https://git.kernel.org/stable/c/a9a7bb801c443a4d9fc623c4a47deb53accb70bb