« Back to list

CVE-2026-89465

Status: ReceivedHigh (8.4)—

In the Linux kernel, the following vulnerability has been resolved:

power: supply: rt9455: quiesce delayed work before teardown

The threaded IRQ handler can queue pwr_rdy_work, max_charging_time_work and batt_presence_work. pwr_rdy_work and batt_presence_work can also queue max_charging_time_work, while batt_presence_work can requeue itself.

rt9455_remove() cancels max_charging_time_work before batt_presence_work. The latter can therefore queue max_charging_time_work after it has already been cancelled:

The IRQ also remains registered until devres cleanup and can queue more work after any of the cancellation calls.

Read full descriptionShow less

If rt9455_hw_init() fails after the IRQ has been requested, probe returns without cancelling work that may already have been queued. A pending callback can then access rt9455_info after it has been freed.

Register rt9455_cancel_all_delayed_works() through devm_add_action_or_reset() right after devm_power_supply_register(). devres invokes the action in reverse registration order, after the managed IRQ has been freed and before rt9455_info is released, so the delayed works are drained in both rt9455_remove() and the probe error path. Cancel pwr_rdy_work and batt_presence_work before max_charging_time_work because both can queue the latter.

This issue was found by an in-house static analysis tool.

Technical details traces, logs and code from the original report
  rt9455_remove()                   workqueue
    cancel pwr_rdy_work
    cancel max_charging_time_work
                                      batt_presence_work queues
                                        max_charging_time_work
    cancel batt_presence_work
    return
    devres frees rt9455_info
                                      max_charging_time_work dereferences
                                        rt9455_info

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

🎯 ATT&CK techniques

How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.

Vulnerabilidad local (AV:L, PR:N) sin interacción que permite denegación de servicio o corrupción de datos al liberar memoria en uso por trabajos diferidos en el kernel de Linux.

Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.

🛡️ ATT&CK mitigations that cover these techniques

Affected technologies (1)

⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2026-89465",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.4,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.5
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "e86d69dd786e94046b8f5be7df1b9a8226a40b2a",
              "lessThan": "442c60c08ec23ac45da0a58877cab05e0a58f4ea",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e86d69dd786e94046b8f5be7df1b9a8226a40b2a",
              "lessThan": "df67c7a2fff8414aa766b8cd5ffe11ec1ca27d02",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e86d69dd786e94046b8f5be7df1b9a8226a40b2a",
              "lessThan": "1b9978433c61a9b46e48832a1ebceee1cf5c9eb4",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e86d69dd786e94046b8f5be7df1b9a8226a40b2a",
              "lessThan": "7323e562f6961e4b7bce3225cde4ecbc78260deb",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e86d69dd786e94046b8f5be7df1b9a8226a40b2a",
              "lessThan": "3e7a1ebc32fad5a558254a478efd401c17a24381",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/power/supply/rt9455_charger.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.2"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.2",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.109",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.50",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/power/supply/rt9455_charger.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-11T20:19:27.533",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/1b9978433c61a9b46e48832a1ebceee1cf5c9eb4",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3e7a1ebc32fad5a558254a478efd401c17a24381",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/442c60c08ec23ac45da0a58877cab05e0a58f4ea",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7323e562f6961e4b7bce3225cde4ecbc78260deb",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/df67c7a2fff8414aa766b8cd5ffe11ec1ca27d02",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\npower: supply: rt9455: quiesce delayed work before teardown\n\nThe threaded IRQ handler can queue pwr_rdy_work,\nmax_charging_time_work and batt_presence_work.  pwr_rdy_work and\nbatt_presence_work can also queue max_charging_time_work, while\nbatt_presence_work can requeue itself.\n\nrt9455_remove() cancels max_charging_time_work before\nbatt_presence_work.  The latter can therefore queue\nmax_charging_time_work after it has already been cancelled:\n\n  rt9455_remove()                   workqueue\n    cancel pwr_rdy_work\n    cancel max_charging_time_work\n                                      batt_presence_work queues\n                                        max_charging_time_work\n    cancel batt_presence_work\n    return\n    devres frees rt9455_info\n                                      max_charging_time_work dereferences\n                                        rt9455_info\n\nThe IRQ also remains registered until devres cleanup and can queue more\nwork after any of the cancellation calls.  If rt9455_hw_init() fails\nafter the IRQ has been requested, probe returns without cancelling work\nthat may already have been queued.  A pending callback can then access\nrt9455_info after it has been freed.\n\nRegister rt9455_cancel_all_delayed_works() through\ndevm_add_action_or_reset() right after devm_power_supply_register().\ndevres invokes the action in reverse registration order, after the\nmanaged IRQ has been freed and before rt9455_info is released, so the\ndelayed works are drained in both rt9455_remove() and the probe error\npath.  Cancel pwr_rdy_work and batt_presence_work before\nmax_charging_time_work because both can queue the latter.\n\nThis issue was found by an in-house static analysis tool."
    }
  ],
  "lastModified": "2026-09-14T13:19:02.870",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}