CVE-2026-89463
In the Linux kernel, the following vulnerability has been resolved:
power: supply: ucs1002: fix use-after-free on remove
ucs1002 has no remove callback, so unbind runs entirely through devm. The alert IRQ handler queues the health_poll delayed work, and the work reschedules itself while the chip reports a bad-health condition. devm frees the alert IRQ, which only synchronizes the handler; it does not cancel the delayed work, which can then run after devm frees the driver data and dereference it.
Register health_poll with devm_delayed_work_autocancel() before the alert IRQ is requested. devm then frees the IRQ before cancelling the work, so the handler can no longer queue it and the work is cancelled before the driver data is freed.
Leer descripción completaMostrar menos
This issue was found by an in-house static analysis tool.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/00c19f8a9a58a318a76fd6f735a8aab3f8ead393
- https://git.kernel.org/stable/c/2ec4d203ecb06d327af67e32097fe8f774838a40
- https://git.kernel.org/stable/c/35242c93d35f391afdc84cef6236b8ad57f1df24
- https://git.kernel.org/stable/c/39b60d615dfa1725c235351fb12bc72e5f8a8d32
- https://git.kernel.org/stable/c/4ca2a4678202f15eb790eb7f1d562061709caea7
- https://git.kernel.org/stable/c/609af0ceeaefdfa42cd01dd060b20f2e41f9a232
- https://git.kernel.org/stable/c/a9a7bb801c443a4d9fc623c4a47deb53accb70bb
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-89463",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "81196e2e57fc5b88f6b8ca98372a3dde047aa49d",
"lessThan": "00c19f8a9a58a318a76fd6f735a8aab3f8ead393",
"versionType": "git"
},
{
"status": "affected",
"version": "81196e2e57fc5b88f6b8ca98372a3dde047aa49d",
"lessThan": "a9a7bb801c443a4d9fc623c4a47deb53accb70bb",
"versionType": "git"
},
{
"status": "affected",
"version": "81196e2e57fc5b88f6b8ca98372a3dde047aa49d",
"lessThan": "2ec4d203ecb06d327af67e32097fe8f774838a40",
"versionType": "git"
},
{
"status": "affected",
"version": "81196e2e57fc5b88f6b8ca98372a3dde047aa49d",
"lessThan": "4ca2a4678202f15eb790eb7f1d562061709caea7",
"versionType": "git"
},
{
"status": "affected",
"version": "81196e2e57fc5b88f6b8ca98372a3dde047aa49d",
"lessThan": "39b60d615dfa1725c235351fb12bc72e5f8a8d32",
"versionType": "git"
},
{
"status": "affected",
"version": "81196e2e57fc5b88f6b8ca98372a3dde047aa49d",
"lessThan": "35242c93d35f391afdc84cef6236b8ad57f1df24",
"versionType": "git"
},
{
"status": "affected",
"version": "81196e2e57fc5b88f6b8ca98372a3dde047aa49d",
"lessThan": "609af0ceeaefdfa42cd01dd060b20f2e41f9a232",
"versionType": "git"
}
],
"programFiles": [
"drivers/power/supply/ucs1002_power.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.10"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.10",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.15.221",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.188",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.157",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.109",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.50",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.4",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/power/supply/ucs1002_power.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-11T20:19:27.283",
"references": [
{
"url": "https://git.kernel.org/stable/c/00c19f8a9a58a318a76fd6f735a8aab3f8ead393",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/2ec4d203ecb06d327af67e32097fe8f774838a40",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/35242c93d35f391afdc84cef6236b8ad57f1df24",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/39b60d615dfa1725c235351fb12bc72e5f8a8d32",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/4ca2a4678202f15eb790eb7f1d562061709caea7",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/609af0ceeaefdfa42cd01dd060b20f2e41f9a232",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a9a7bb801c443a4d9fc623c4a47deb53accb70bb",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\npower: supply: ucs1002: fix use-after-free on remove\n\nucs1002 has no remove callback, so unbind runs entirely through devm.\nThe alert IRQ handler queues the health_poll delayed work, and the work\nreschedules itself while the chip reports a bad-health condition. devm\nfrees the alert IRQ, which only synchronizes the handler; it does not\ncancel the delayed work, which can then run after devm frees the driver\ndata and dereference it.\n\nRegister health_poll with devm_delayed_work_autocancel() before the\nalert IRQ is requested. devm then frees the IRQ before cancelling the\nwork, so the handler can no longer queue it and the work is cancelled\nbefore the driver data is freed.\n\nThis issue was found by an in-house static analysis tool."
}
],
"lastModified": "2026-09-14T13:19:02.620",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}