Description
In the Linux kernel, the following vulnerability has been resolved:

power: supply: ab8500_fg: fix use-after-free on remove

ab8500_fg_remove() destroys the driver workqueue while the threaded
interrupt handlers are still armed; they are devm-managed and freed
only after ->remove() returns, so a handler that fires in that
window queues work on the freed workqueue.

Tear the workqueue down through devm instead, registering its cleanup
after the power supply and before the interrupt requests. devm then
frees the interrupts first, so the handlers can no longer queue work,
before disabling the delayed and plain work items and destroying the
workqueue. Disabling the items, rather than cancelling them, keeps
them disabled so no producer (including the power-supply
external_power_changed callback) can requeue them.

Found by an in-house static analysis tool.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Code Execution
Action: Patch Immediately
AI Analysis

Impact

A use‑after‑free occurs in the Linux ab8500 fuel‑gauge driver when the kernel removes the driver. The removal function destroys the driver workqueue while threaded interrupt handlers are still armed. Those handlers can subsequently queue work on a freed queue, corrupting memory. This flaw is a classic Use‑After‑Free, which can lead to arbitrary kernel code execution or a system crash during the removal window.

Affected Systems

The bug is embedded in the ab8500 fuel‑gauge driver that ships with all Linux kernel versions that include support for this hardware. Any distribution using a kernel that has not applied the upstream fix is susceptible. Since no specific patch level is mentioned, all kernels prior to the commit that resolves the issue may be affected.

Risk and Exploitability

The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating that exploitation is unlikely in the wider ecosystem. However, exploitation is possible when an attacker can trigger the driver unload or system shutdown while interrupts are still active, which could lead to arbitrary code execution in kernel mode. The attack vector is inferred from the description: it most likely requires local or privileged access to cause the driver to unload or to provoke interrupt activity during shutdown. The overall risk is high due to the severity of the flaw, but the likelihood of exploitation remains low in typical environments.

Generated by OpenCVE AI on September 18, 2026 at 11:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a release that includes the ab8500_fg_remove fix or apply the upstream commit that resolves the use‑after‑free.
  • If a kernel upgrade cannot be performed immediately, disable or unload the ab8500 fuel‑gauge driver to eliminate the removal window that triggers the flaw.
  • During system shutdown or driver unload procedures, ensure that no external interrupts or power‑supply events can occur; avoid enabling external‑power change callbacks that might re‑queue work items.

Generated by OpenCVE AI on September 18, 2026 at 11:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 11:15:00 +0000


Fri, 18 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: power: supply: ab8500_fg: fix use-after-free on remove ab8500_fg_remove() destroys the driver workqueue while the threaded interrupt handlers are still armed; they are devm-managed and freed only after ->remove() returns, so a handler that fires in that window queues work on the freed workqueue. Tear the workqueue down through devm instead, registering its cleanup after the power supply and before the interrupt requests. devm then frees the interrupts first, so the handlers can no longer queue work, before disabling the delayed and plain work items and destroying the workqueue. Disabling the items, rather than cancelling them, keeps them disabled so no producer (including the power-supply external_power_changed callback) can requeue them. Found by an in-house static analysis tool.
Title power: supply: ab8500_fg: fix use-after-free on remove
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-03T10:56:41.231Z

Reserved: 2026-09-11T19:38:34.767Z

Link: CVE-2026-89797

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:44.547

Modified: 2026-10-03T11:17:43.733

Link: CVE-2026-89797

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T11:45:07Z

Weaknesses