Description
In the Linux kernel, the following vulnerability has been resolved:

power: supply: sc2731_charger: cancel work on remove

The USB notifier and initial charger detection can schedule info->work.
The remove path unregisters the notifier, but does not cancel queued or
running work before the devm-allocated driver data is released.

Set the platform drvdata used by remove, then cancel the work after
unregistering the notifier.

This issue was found by a static analysis tool.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free leading to memory corruption or system crash
Action: Apply Patch
AI Analysis

Impact

The SC2731 charger driver in the Linux kernel fails to cancel pending work when the charger device is removed. The removal path unregisters the USB notifier while leaving queued or running work that references the driver’s data. When that data is freed, the work may execute on stale memory, creating a use‑after‑free condition (CWE‑416). This flaw can trigger kernel memory corruption, a panic, or potentially provide an attacker with a privilege escalation path if an exploit is crafted.

Affected Systems

All Linux kernel distributions that include the sc2731 charger driver module are affected. The issue remains present in currently released kernel versions until the patch is applied, affecting any device that supports SC2731 hardware: desktop laptops, embedded boards, or any system with this charger controller driver.

Risk and Exploitability

The EPSS score is below 1 %, indicating a low likelihood of exploitation in the wild, and the flaw is not listed in the CISA KEV catalog, so no public exploits have been reported. Nonetheless, an attacker with local or limited physical access—such as a malicious USB power source or power‑cycle attack—could trigger charger removal and exercise the use‑after‑free. Because the flaw occurs at kernel privilege, successful exploitation could lead to complete system compromise. The lack of an explicit CVSS score means the impact is inferred from the kernel context and the nature of the defect, suggesting high severity if exploited.

Generated by OpenCVE AI on September 19, 2026 at 13:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the patch for the SC2731 driver workqueue cancellation
  • If an upgrade cannot be performed immediately, disable the SC2731 charger driver module to prevent the problematic work from being scheduled
  • After applying the fix or disabling the driver, reboot the system to ensure all pending work queues are cleared

Generated by OpenCVE AI on September 19, 2026 at 13:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: power: supply: sc2731_charger: cancel work on remove The USB notifier and initial charger detection can schedule info->work. The remove path unregisters the notifier, but does not cancel queued or running work before the devm-allocated driver data is released. Set the platform drvdata used by remove, then cancel the work after unregistering the notifier. This issue was found by a static analysis tool.
Title power: supply: sc2731_charger: cancel work on remove
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:27.050Z

Reserved: 2026-09-11T19:38:34.810Z

Link: CVE-2026-90394

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:39.040

Modified: 2026-09-17T17:17:39.040

Link: CVE-2026-90394

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T13:30:13Z

Weaknesses