Impact
The Linux kernel’s bq256xx power‑supply driver contains a use‑after‑free flaw (CWE‑825). When the USB‑PHY notifier queues a work item, its handler calls power_supply_changed(bq->charger). The reset action registered by devm is freed before that work item runs because it is unregistered prior to the power supplies; if the work item is still queued during cleanup, it dereferences a charger object that has already been freed, which can trigger a kernel panic and a denial of service.
Affected Systems
All installations of the bq256xx driver in its unpatched form are affected. The CPE indicates the base Linux kernel; the CVE does not specify a the reset the older notifier ordering is vulnerable.
Risk and Exploitability
The EPSS score is below 1 %, signaling a low likelihood of widespread exploitation and a primarily local attack surface. With a CVSS score of 4.4, the vulnerability is considered moderate. It is not listed in the CISA KEV catalog, and no public exploits are known. The attack vector is inferred to be local, triggered by USB power events that enqueue usb_work. As a result, the risk is moderate and remediation through a kernel update is the advised path.
OpenCVE Enrichment
Debian DSA