Description
In the Linux kernel, the following vulnerability has been resolved:

power: supply: twl4030_charger: cancel workers via devm

bci is devm-allocated. Two workers (bci->work and bci->current_worker)
dereference it. twl4030_bci_remove() disables charging and masks
interrupts. It cancels neither worker. A worker pending at remove() can
run after devm frees bci.

The USB transceiver comes from devm_usb_get_phy_by_node(). devm
unregisters its notifier only after remove() returns. A cancel_work_sync()
in remove() can then race a notifier reschedule. devm_work_autocancel()
and devm_delayed_work_autocancel() avoid that. They cancel the workers
during devm release, before bci is freed.

The current_worker is registered first, since devm will cancel in
reverse order and bci->work can reschedule current_worker.

[Move comment about order into the commit message]
Published: 2026-09-11
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Use-after-free that can crash the kernel
Action: Apply Patch
AI Analysis

Impact

A race condition in the Linux twl4030 charger driver allows workers that run after the driver’s resources have been released to dereference a freed structure allocated by devm, leading to a use‑after‑free that can cause the kernel to crash.

Affected Systems

The vulnerability affects any Linux kernel that still contains the unpatched twl4030 charger driver code. All distributions with kernel builds that have not incorporated the upstream patch that cancels both workers before freeing the devm object remain vulnerable. The specific kernel releases are not listed in the advisory, but any version where the driver code is unchanged is impacted.

Risk and Exploitability

The CVSS base score of 4.4 indicates moderate severity, while the EPSS probability of exploitation is very low. The issue requires local control over the device removal to trigger the race, making it unlikely to be exploited remotely or by an unauthenticated attacker. The vulnerability is not listed in CISA’s KEV catalog, indicating no known exploitation activity.

Generated by OpenCVE AI on September 21, 2026 at 01:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a kernel that includes the fix for the twl4030 charger driver, which removes both work queues before freeing the devm object.
  • If a kernel upgrade is not immediately feasible, apply the specific commit that corrects the cancellation logic to the driver source or cherry‑pick it into the running kernel.
  • Disable or unload the twl4030 charger driver at boot or once the device is no longer needed to prevent the race condition from occurring.

Generated by OpenCVE AI on September 21, 2026 at 01:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: power: supply: twl4030_charger: cancel workers via devm bci is devm-allocated. Two workers (bci->work and bci->current_worker) dereference it. twl4030_bci_remove() disables charging and masks interrupts. It cancels neither worker. A worker pending at remove() can run after devm frees bci. The USB transceiver comes from devm_usb_get_phy_by_node(). devm unregisters its notifier only after remove() returns. A cancel_work_sync() in remove() can then race a notifier reschedule. devm_work_autocancel() and devm_delayed_work_autocancel() avoid that. They cancel the workers during devm release, before bci is freed. The current_worker is registered first, since devm will cancel in reverse order and bci->work can reschedule current_worker. [Move comment about order into the commit message]
Title power: supply: twl4030_charger: cancel workers via devm
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:00:03.171Z

Reserved: 2026-09-11T19:38:34.708Z

Link: CVE-2026-89464

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:27.410

Modified: 2026-09-14T13:19:02.747

Link: CVE-2026-89464

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:43:25Z

Links: CVE-2026-89464 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T01:15:03Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference