CVE-2026-89464
Received Received - Intake

Use-After-Free in Linux Kernel TWL4030 Charger Driver

Vulnerability report for CVE-2026-89464, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: power: supply: twl4030_charger: cancel workers via devm bci is devm-allocated. Two workers (bci->work and bci->current_worker) dereference it. twl4030_bci_remove() disables charging and masks interrupts. It cancels neither worker. A worker pending at remove() can run after devm frees bci. The USB transceiver comes from devm_usb_get_phy_by_node(). devm unregisters its notifier only after remove() returns. A cancel_work_sync() in remove() can then race a notifier reschedule. devm_work_autocancel() and devm_delayed_work_autocancel() avoid that. They cancel the workers during devm release, before bci is freed. The current_worker is registered first, since devm will cancel in reverse order and bci->work can reschedule current_worker. [Move comment about order into the commit message]

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves improper handling of workers in the twl4030_charger power supply subsystem. The issue occurs because two workers dereference a device-managed (devm) allocated structure (bci) that gets freed during cleanup. The remove function cancels neither worker, allowing a pending worker to run after the structure is freed, leading to a use-after-free condition.

Detection Guidance

This vulnerability is specific to the Linux kernel's power supply subsystem (twl4030_charger) and involves improper handling of workers during device removal. Detection requires checking kernel logs for related errors or kernel version checks. Commands: dmesg | grep twl4030_charger, uname -a, journalctl -k | grep twl4030_charger.

Impact Analysis

This vulnerability could lead to system instability or crashes due to use-after-free errors. Attackers might exploit it to execute arbitrary code or cause denial-of-service conditions on affected systems running vulnerable Linux kernel versions.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or other common standards and regulations. The issue is specific to the Linux kernel's power supply subsystem and involves a race condition in worker cancellation during device removal. There is no indication that this vulnerability impacts data protection, privacy, or security controls required by these standards.

Mitigation Strategies

Apply the latest kernel updates from your distribution to ensure the fix is included. If immediate patching is not possible, monitor for related errors in logs and avoid hot-unplugging affected devices until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89464. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart