CVE-2026-89463
Received Received - Intake

Use-After-Free in Linux Kernel ucs1002 Power Supply Driver

Vulnerability report for CVE-2026-89463, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: power: supply: ucs1002: fix use-after-free on remove ucs1002 has no remove callback, so unbind runs entirely through devm. The alert IRQ handler queues the health_poll delayed work, and the work reschedules itself while the chip reports a bad-health condition. devm frees the alert IRQ, which only synchronizes the handler; it does not cancel the delayed work, which can then run after devm frees the driver data and dereference it. Register health_poll with devm_delayed_work_autocancel() before the alert IRQ is requested. devm then frees the IRQ before cancelling the work, so the handler can no longer queue it and the work is cancelled before the driver data is freed. This issue was found by an in-house static analysis tool.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-09-30
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
power supply ucs1002

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a use-after-free issue in the Linux kernel's power supply subsystem, specifically in the ucs1002 driver. The problem occurs because the driver lacks a proper remove callback, causing the device unbind process to rely entirely on devm (device managed resources). When the device is removed, the alert IRQ handler continues to queue delayed work that references freed driver data, leading to a use-after-free condition.

Detection Guidance

This vulnerability is specific to the Linux kernel's power supply subsystem, particularly the ucs1002 driver. Detection requires checking if the affected driver is loaded and if the system is running a vulnerable kernel version. Use commands like 'lsmod | grep ucs1002' to check if the driver is loaded and 'uname -a' to verify the kernel version. If the driver is loaded and the kernel is affected, further investigation is needed.

Impact Analysis

This vulnerability could cause system instability or crashes if exploited. An attacker with local access might trigger the use-after-free condition, potentially leading to kernel memory corruption, denial of service, or privilege escalation. Systems using the ucs1002 power supply driver are affected.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or other common standards and regulations. It is a use-after-free issue in the Linux kernel's power supply subsystem, specifically in the ucs1002 driver, which could lead to system instability or crashes but does not involve data privacy or security breaches relevant to these regulations.

Mitigation Strategies

Apply the latest kernel update provided by your Linux distribution to patch this vulnerability. If an update is not immediately available, consider disabling the ucs1002 driver by blacklisting it using 'echo 'blacklist ucs1002' | sudo tee /etc/modprobe.d/blacklist-ucs1002.conf' and then running 'sudo update-initramfs -u'. Monitor vendor advisories for official patches.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89463. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart