Description
In the Linux kernel, the following vulnerability has been resolved:

power: supply: lp8788-charger: fix use-after-free on remove

lp8788_charger_remove() flushes charger_work before unregistering the
IRQs. An IRQ thread can queue charger_work after flush_work() has
returned. The work can then run after devres frees pchg and dereference
it in lp8788_charger_event().

Unregister the IRQs first. free_irq() waits for any running threaded
handler, so no handler can queue more work afterwards. Then use
cancel_work_sync() to cancel pending work or wait for running work to
finish.

This issue was found by an in-house static analysis tool.
Published: 2026-09-11
Score: 4.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via kernel use‑after‑free in the lp8788 charger driver
Action: Immediate Patch
AI Analysis

Impact

An improper ordering of work queue flushing and IRQ unregistration in the lp8788 charger driver causes a use‑after‑free when the device is removed. The driver flushes pending work too early and then cancels the IRQs afterwards, allowing a worker thread scheduled after the flush to dereference freed memory. This flaw falls under CWE‑364 and can materialize as a kernel panic or other system instability. Attackers would need privileged or local access to trigger the removal sequence.

Affected Systems

All Linux kernel builds that include the lp8788 charger module are potentially affected. No exact kernel release numbers are specified, so any kernel that compiles the driver without the patch carries the risk.

Risk and Exploitability

The CVSS score of 4.1 indicates moderate severity, and the EPSS score of less than 1% suggests a very low probability of exploitation. The flaw requires the device to be removed or the driver unloaded, which is typically a local or privileged action; remote exploitation is not implied. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on September 21, 2026 at 01:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a kernel version that incorporates the patch in which interrupts are unregistered before work is flushed and cancel_work_sync is used to prevent dangling work registrations.
  • If a kernel upgrade cannot be applied immediately, avoid unloading or removing the lp8788 charger module during normal operation; for example, disable hot‑plug removal for that device or lock the module in memory.
  • Ensure that the charger hardware is fully powered off before the driver is removed, such as by following the board’s shutdown sequence or disabling power management events that trigger controller removal.

Generated by OpenCVE AI on September 21, 2026 at 01:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-364
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: power: supply: lp8788-charger: fix use-after-free on remove lp8788_charger_remove() flushes charger_work before unregistering the IRQs. An IRQ thread can queue charger_work after flush_work() has returned. The work can then run after devres frees pchg and dereference it in lp8788_charger_event(). Unregister the IRQs first. free_irq() waits for any running threaded handler, so no handler can queue more work afterwards. Then use cancel_work_sync() to cancel pending work or wait for running work to finish. This issue was found by an in-house static analysis tool.
Title power: supply: lp8788-charger: fix use-after-free on remove
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:43:27.906Z

Reserved: 2026-09-11T19:38:34.709Z

Link: CVE-2026-89468

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:27.910

Modified: 2026-09-11T20:19:27.910

Link: CVE-2026-89468

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:43:27Z

Links: CVE-2026-89468 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T01:30:08Z

Weaknesses
  • CWE-364

    Signal Handler Race Condition