Description
In the Linux kernel, the following vulnerability has been resolved:

auxdisplay: charlcd: cancel backlight work on registration failure

With CONFIG_CHARLCD_BL_FLASH, charlcd_init() schedules bl_work before
charlcd_register() calls misc_register(). If registration fails, the
caller frees the charlcd object while delayed work still contains its
address.

Add charlcd_deinit() to cancel the delayed work and turn the backlight
off. Use it for both registration rollback and normal unregistration.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free leading to memory corruption
Action: Patch Now
AI Analysis

Impact

In the Linux kernel the charlcd driver with CONFIG_CHARLCD_BL_FLASH schedules a delayed backlight work item before the driver’s misc device is registered. If registration fails, the driver frees its internal object while the delayed work still references it, creating a use‑after‑free condition that can lead to arbitrary memory corruption and system crashes. The weakness is a classic improper release of resource flaw, CWE‑825.

Affected Systems

All Linux kernel builds that compile the charlcd driver with the CONFIG_CHARLCD_BL_FLASH option enabled are affected, including any distribution kernel that has not yet integrated the fix that cancels the delayed work during deinitialization. The vulnerability resides in the core Linux kernel driver code, not in a single vendor’s custom distribution.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, but the EPSS score is less than 1% and it is not listed in the CISA KEV catalog, suggesting a low likelihood of current exploitation. Based on the description, it is inferred that the attack vector is limited to local or privileged accounts that can trigger a registration failure; there is no exposed user‑space interface to induce the failure. Consequently, the overall risk remains moderate to low for typical production systems, but any system running an unpatched kernel with this configuration should be upgraded or patched promptly.

Generated by OpenCVE AI on September 15, 2026 at 21:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest kernel update that implements charlcd_deinit to cancel delayed work and turn off the backlight during registration rollback and normal unregistration.
  • Disable the CONFIG_CHARLCD_BL_FLASH compile option so that backlight work is scheduled only after successful registration.
  • If the charlcd driver is unused, blacklist or remove the module to eliminate the vulnerable code path.

Generated by OpenCVE AI on September 15, 2026 at 21:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: auxdisplay: charlcd: cancel backlight work on registration failure With CONFIG_CHARLCD_BL_FLASH, charlcd_init() schedules bl_work before charlcd_register() calls misc_register(). If registration fails, the caller frees the charlcd object while delayed work still contains its address. Add charlcd_deinit() to cancel the delayed work and turn the backlight off. Use it for both registration rollback and normal unregistration.
Title auxdisplay: charlcd: cancel backlight work on registration failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:01:12.853Z

Reserved: 2026-09-11T19:38:34.729Z

Link: CVE-2026-89585

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:42.910

Modified: 2026-09-14T13:19:12.737

Link: CVE-2026-89585

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:44:50Z

Links: CVE-2026-89585 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:45:17Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference