CVE-2026-89797
In the Linux kernel, the following vulnerability has been resolved:
power: supply: ab8500_fg: fix use-after-free on remove
ab8500_fg_remove() destroys the driver workqueue while the threaded interrupt handlers are still armed; they are devm-managed and freed only after ->remove() returns, so a handler that fires in that window queues work on the freed workqueue.
Tear the workqueue down through devm instead, registering its cleanup after the power supply and before the interrupt requests. devm then frees the interrupts first, so the handlers can no longer queue work, before disabling the delayed and plain work items and destroying the workqueue.
Leer descripción completaMostrar menos
Disabling the items, rather than cancelling them, keeps them disabled so no producer (including the power-supply external_power_changed callback) can requeue them.
Found by an in-house static analysis tool.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-89797",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "13151631b5bd06a1511353bb221079bbd76606c3",
"lessThan": "c2ce9b8f325f522e10e4d262b37ae49deb83e79b",
"versionType": "git"
},
{
"status": "affected",
"version": "13151631b5bd06a1511353bb221079bbd76606c3",
"lessThan": "c660c017dec1fd7cd88e1103c5ae1aae6ce636bf",
"versionType": "git"
},
{
"status": "affected",
"version": "13151631b5bd06a1511353bb221079bbd76606c3",
"lessThan": "013731074ab6a8d11ec209eee64c5b2656954479",
"versionType": "git"
},
{
"status": "affected",
"version": "13151631b5bd06a1511353bb221079bbd76606c3",
"lessThan": "75b1e88d34254f4fb7753345e21bfee47abddd7f",
"versionType": "git"
}
],
"programFiles": [
"drivers/power/supply/ab8500_fg.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "3.4"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "3.4",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.12.112",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.51",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.5",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/power/supply/ab8500_fg.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-16T11:16:44.547",
"references": [
{
"url": "https://git.kernel.org/stable/c/013731074ab6a8d11ec209eee64c5b2656954479",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/75b1e88d34254f4fb7753345e21bfee47abddd7f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c2ce9b8f325f522e10e4d262b37ae49deb83e79b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c660c017dec1fd7cd88e1103c5ae1aae6ce636bf",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\npower: supply: ab8500_fg: fix use-after-free on remove\n\nab8500_fg_remove() destroys the driver workqueue while the threaded\ninterrupt handlers are still armed; they are devm-managed and freed\nonly after ->remove() returns, so a handler that fires in that\nwindow queues work on the freed workqueue.\n\nTear the workqueue down through devm instead, registering its cleanup\nafter the power supply and before the interrupt requests. devm then\nfrees the interrupts first, so the handlers can no longer queue work,\nbefore disabling the delayed and plain work items and destroying the\nworkqueue. Disabling the items, rather than cancelling them, keeps\nthem disabled so no producer (including the power-supply\nexternal_power_changed callback) can requeue them.\n\nFound by an in-house static analysis tool."
}
],
"lastModified": "2026-10-03T11:17:43.733",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}