CVE-2026-89472
Received Received - Intake

Use-After-Free in Linux Kernel Power Supply Subsystem

Vulnerability report for CVE-2026-89472, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-13

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: power: supply: charger-manager: register regulators before exposing sysfs charger_manager_remove() and the err_reg_extcon probe error path free each charger regulator with regulator_put() before tearing down the power_supply sysfs entries (power_supply_unregister()). charger_manager_remove() also calls try_charger_enable(cm, false) after the regulator_put() loop. A concurrent write to a charger's externally_control sysfs attribute that lands between regulator_put() and power_supply_unregister() can run charger_externally_control_store() and call try_charger_enable(), which, when charging is enabled, dereferences the already-freed consumer handle. When charging is enabled, try_charger_enable(cm, false) in .remove() also dereferences the freed handles directly. Both leave use-after-free windows. Symmetrically, probe registers the sysfs entries (power_supply_register) before acquiring the regulators (regulator_get, inside charger_manager_register_extcon), so userspace can reach externally_control before the regulators are available. Split charger_manager_register_extcon() on the sync/async boundary: charger_manager_get_regulators() (regulator_get only, no async producer) now runs before power_supply_register() so sysfs is not live before regulators are available, and charger_manager_register_extcon() keeps only the extcon notifier/work setup, still after power_supply_register() so a power_supply_register() failure cannot reach extcon setup. This keeps the sysfs setup/teardown ordering symmetric without introducing an asynchronous producer on the earlier probe-error path. Move power_supply_unregister() and try_charger_enable(cm, false) ahead of the regulator_put() loop on both teardown paths, and adjust err_reg_extcon (power_supply_unregister() then fall through err_regulator for regulator_put(); get_regulators self-rolls back on its own failure). This does not address the separate extcon-notifier-driven deref of the same handles, which needs its own synchronization design. Found by an in-house static analysis tool.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-13
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a use-after-free issue in the charger-manager component. The problem occurs when regulators are freed before sysfs entries are removed, allowing a concurrent write to trigger a use-after-free when dereferencing already-freed consumer handles. The fix reorders operations to ensure proper cleanup and prevent race conditions.

Detection Guidance

This vulnerability is specific to the Linux kernel's charger-manager subsystem and involves use-after-free issues in regulator and power_supply handling. Detection requires checking kernel logs for crashes or warnings related to charger-manager or power_supply operations. Commands like dmesg | grep -i 'charger_manager' or journalctl -k | grep -i 'power_supply' may help identify related errors.

Impact Analysis

This vulnerability could lead to system instability or crashes if exploited. An attacker with local access might trigger a use-after-free condition, potentially causing denial-of-service or privilege escalation. Systems using the affected Linux kernel component are at risk.

Compliance Impact

This vulnerability involves a use-after-free issue in the Linux kernel's charger manager, which could lead to memory corruption or crashes. While it does not directly impact data privacy or security controls required by GDPR or HIPAA, such kernel-level vulnerabilities could potentially compromise system stability or integrity, indirectly affecting compliance if they lead to unauthorized data access or service disruptions.

Mitigation Strategies

Apply the latest kernel patches from your Linux distribution to resolve the use-after-free issue in the charger-manager subsystem. If immediate patching is not possible, consider disabling the charger-manager feature or restricting access to sysfs attributes related to charger control until the fix is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89472. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart