Impact
An improper ordering of work queue flushing and IRQ unregistration in the lp8788 charger driver causes a use‑after‑free when the device is removed. The driver flushes pending work too early and then cancels the IRQs afterwards, allowing a worker thread scheduled after the flush to dereference freed memory. This flaw falls under CWE‑364 and can materialize as a kernel panic or other system instability. Attackers would need privileged or local access to trigger the removal sequence.
Affected Systems
All Linux kernel builds that include the lp8788 charger module are potentially affected. No exact kernel release numbers are specified, so any kernel that compiles the driver without the patch carries the risk.
Risk and Exploitability
The CVSS score of 4.1 indicates moderate severity, and the EPSS score of less than 1% suggests a very low probability of exploitation. The flaw requires the device to be removed or the driver unloaded, which is typically a local or privileged action; remote exploitation is not implied. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
Debian DSA