Bug 2532107 (CVE-2026-89464) - CVE-2026-89464 kernel: Linux kernel: twl4030_charger: Use-after-free vulnerability leading to denial of service
Summary: CVE-2026-89464 kernel: Linux kernel: twl4030_charger: Use-after-free vulnerab...
Keywords:
Status: NEW
Alias: CVE-2026-89464
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-11 20:41 UTC by OSIDB Bzimport
Modified: 2026-09-11 20:58 UTC (History)
15 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-11 20:41:18 UTC
In the Linux kernel, the following vulnerability has been resolved:

power: supply: twl4030_charger: cancel workers via devm

bci is devm-allocated. Two workers (bci->work and bci->current_worker)
dereference it. twl4030_bci_remove() disables charging and masks
interrupts. It cancels neither worker. A worker pending at remove() can
run after devm frees bci.

The USB transceiver comes from devm_usb_get_phy_by_node(). devm
unregisters its notifier only after remove() returns. A cancel_work_sync()
in remove() can then race a notifier reschedule. devm_work_autocancel()
and devm_delayed_work_autocancel() avoid that. They cancel the workers
during devm release, before bci is freed.

The current_worker is registered first, since devm will cancel in
reverse order and bci->work can reschedule current_worker.

[Move comment about order into the commit message]


Note You need to log in before you can comment on or make changes to this bug.