Impact
The charger‑manager driver in the Linux kernel has a use‑after‑free bug that can be triggered during module removal or error recovery. After freeing regulator objects, the driver leaves the power_supply sysfs interface live, so a concurrent write to the charger’s externally_control sysfs attribute can reach a function that dereferences an already‑freed consumer handle. This can cause a kernel crash or denial of service and is associated with CWE‑364, a potential interlock condition.
Affected Systems
Any Linux kernel that includes the charger‑manager component is potentially affected. The vulnerability is present in the core kernel code, whether the charger module is compiled in or loaded as a module. No specific kernel release ranges are mentioned, so all current builds that ship the charger‑manager driver are at risk.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, but the EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a local user or process with write permission to the charger’s externally_control sysfs attribute, which can trigger the use‑after‑free when the driver is unloading or encountering an error. Root privileges would also allow an attacker to enforce the race, but a lesser privileged user with writable access to the relevant sysfs path can also trigger a denial of service.
OpenCVE Enrichment
Debian DSA