Impact
A race condition in the Linux kernel occurs when the isp1704 charger work is not canceled before the power supply is removed. The removal path unregisters the notifier and power supply without waiting for queued or running work, which can lead to a use‑after‑free scenario. If the work accesses freed memory, this could trigger a kernel panic or other undefined behaviour, compromising system stability and availability.
Affected Systems
The vulnerability affects all Linux kernel builds that include the isp1704 charger driver at any version before the patch is applied. No specific vendor or product version is listed, meaning any system running the affected kernel code is potentially impacted.
Risk and Exploitability
The EPSS score of less than 1% indicates a very low probability of exploitation, and the flaw is not currently listed in CISA’s Known Exploited Vulnerabilities catalog. Because the flaw resides in kernel code and requires the charger device to be removed while work may still be pending, the attack vector is local and would typically involve privileged users or specialized hardware manipulation to trigger the race condition. The absence of an active exploitation campaign, combined with the low EPSS, suggests a moderate risk mainly associated with accidental system instability rather than active exploitation.
OpenCVE Enrichment
Debian DLA
Debian DSA