Description
In the Linux kernel, the following vulnerability has been resolved:

power: supply: lp8727: fix use-after-free in lp8727_release_irq()

lp8727_isr_func(), the threaded IRQ handler, is the only caller that arms
pchg->work via schedule_delayed_work(). lp8727_release_irq() currently
cancels the work before freeing the IRQ, so an IRQ delivered in between
can re-arm the work through the threaded handler. After .remove returns
the devm layer frees pchg while lp8727_delayed_func() may still run and
dereference it.

Free the IRQ first so the threaded handler is quiesced and can no longer
queue work, then cancel the delayed work to drain the final generation.

This issue was found by an in-house static analysis tool.
Published: 2026-09-11
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Use‑after‑free in the LP8727 power‑supply driver can cause kernel crashes or memory corruption
Action: Update Kernel
AI Analysis

Impact

A use‑after‑free flaw in the Linux kernel’s LP8727 power‑supply driver allows a delayed work task to be scheduled after the driver has released the IRQ and freed‑arm the work, and when the device is removed, the work may run on a freed pointer, potentially crashing the kernel or corrupting memory. The flaw represents a classic CWE‑825 scenario that exposes the kernel to arbitrary memory corruption from privileged driver code.

Affected Systems

Any installation of the Linux kernel that includes the LP8727 power‑supply driver utilizes commit 6ab3128292df67295de1b2a86f21d89cf6612a7e. The driver is used on systems equipped with the LP8727 power‑management chip, and no specific kernel version information is available for impacted kernels.

Risk and Exploitability

The CVSS score of 8.4 denotes high severity. EPSS remains < 1%, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is inferred to be local privilege or a maliciously constructed interrupt. Successful exploitation could lead to kernel crashes, memory corruption, or privilege escalation. However, achieving a successful attack would require a crafted interrupt or manipulation of the LP8727 device, which is unlikely in normal operation.

Generated by OpenCVE AI on September 15, 2026 at 22:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel release or update that includes commit 6ab3128292df67295de1b2a86f21d89cf6612a7e or later, which reorders IRQ release and work cancellation.
  • Backport the changes from commit 6ab3128292df67295de1b2a86f21d89cf6612a7e to your current kernel source, then rebuild and install the updated kernel.
  • Unload or disable the LP8727 driver or block its IRQ from the system until the patched kernel is deployed.

Generated by OpenCVE AI on September 15, 2026 at 22:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: power: supply: lp8727: fix use-after-free in lp8727_release_irq() lp8727_isr_func(), the threaded IRQ handler, is the only caller that arms pchg->work via schedule_delayed_work(). lp8727_release_irq() currently cancels the work before freeing the IRQ, so an IRQ delivered in between can re-arm the work through the threaded handler. After .remove returns the devm layer frees pchg while lp8727_delayed_func() may still run and dereference it. Free the IRQ first so the threaded handler is quiesced and can no longer queue work, then cancel the delayed work to drain the final generation. This issue was found by an in-house static analysis tool.
Title power: supply: lp8727: fix use-after-free in lp8727_release_irq()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:00:06.392Z

Reserved: 2026-09-11T19:38:34.709Z

Link: CVE-2026-89469

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:28.023

Modified: 2026-09-14T13:19:03.157

Link: CVE-2026-89469

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:43:28Z

Links: CVE-2026-89469 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T23:00:16Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference