* CVE-2026-89469: power: supply: lp8727: fix use-after-free in lp8727_release_irq()
@ 2026-09-11 19:42 Greg Kroah-Hartman
0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-09-11 19:42 UTC (permalink / raw)
To: linux-cve-announce; +Cc: Greg Kroah-Hartman
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
power: supply: lp8727: fix use-after-free in lp8727_release_irq()
lp8727_isr_func(), the threaded IRQ handler, is the only caller that arms
pchg->work via schedule_delayed_work(). lp8727_release_irq() currently
cancels the work before freeing the IRQ, so an IRQ delivered in between
can re-arm the work through the threaded handler. After .remove returns
the devm layer frees pchg while lp8727_delayed_func() may still run and
dereference it.
Free the IRQ first so the threaded handler is quiesced and can no longer
queue work, then cancel the delayed work to drain the final generation.
This issue was found by an in-house static analysis tool.
The Linux kernel CVE team has assigned CVE-2026-89469 to this issue.
Affected and fixed versions
===========================
Issue introduced in 3.7 with commit d71fda01610269e3aaedd451f8d3e34cdf550036 and fixed in 6.12.109 with commit 80d4e40a85ba524e66c8c748aa7bb19eaf2f69df
Issue introduced in 3.7 with commit d71fda01610269e3aaedd451f8d3e34cdf550036 and fixed in 6.18.50 with commit ab6b1ad710bed7931540733ce145493fece8ceef
Issue introduced in 3.7 with commit d71fda01610269e3aaedd451f8d3e34cdf550036 and fixed in 7.2.4 with commit 6ab3128292df67295de1b2a86f21d89cf6612a7e
Issue introduced in 3.7 with commit d71fda01610269e3aaedd451f8d3e34cdf550036 and fixed in 7.3-rc1 with commit ceb6ac43b0f591722401922ceb958ce2616935e0
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-89469
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
drivers/power/supply/lp8727_charger.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/80d4e40a85ba524e66c8c748aa7bb19eaf2f69df
https://git.kernel.org/stable/c/ab6b1ad710bed7931540733ce145493fece8ceef
https://git.kernel.org/stable/c/6ab3128292df67295de1b2a86f21d89cf6612a7e
https://git.kernel.org/stable/c/ceb6ac43b0f591722401922ceb958ce2616935e0
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2026-09-11 19:51 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-11 19:42 CVE-2026-89469: power: supply: lp8727: fix use-after-free in lp8727_release_irq() Greg Kroah-Hartman
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.