Description
In the Linux kernel, the following vulnerability has been resolved:

power: supply: isp1704_charger: cancel work on remove

The USB notifier and initial VBUS detection can schedule isp->work. The
remove path unregisters the notifier and power supply, but does not wait
for queued or running work before tearing down the power supply state.

Cancel the work after unregistering the notifier. Do this before
unregistering the power supply.

This issue was found by a static analysis tool.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Use‑after‑free potentially causing kernel crash
Action: Patch
AI Analysis

Impact

A race condition in the Linux kernel occurs when the isp1704 charger work is not canceled before the power supply is removed. The removal path unregisters the notifier and power supply without waiting for queued or running work, which can lead to a use‑after‑free scenario. If the work accesses freed memory, this could trigger a kernel panic or other undefined behaviour, compromising system stability and availability.

Affected Systems

The vulnerability affects all Linux kernel builds that include the isp1704 charger driver at any version before the patch is applied. No specific vendor or product version is listed, meaning any system running the affected kernel code is potentially impacted.

Risk and Exploitability

The EPSS score of less than 1% indicates a very low probability of exploitation, and the flaw is not currently listed in CISA’s Known Exploited Vulnerabilities catalog. Because the flaw resides in kernel code and requires the charger device to be removed while work may still be pending, the attack vector is local and would typically involve privileged users or specialized hardware manipulation to trigger the race condition. The absence of an active exploitation campaign, combined with the low EPSS, suggests a moderate risk mainly associated with accidental system instability rather than active exploitation.

Generated by OpenCVE AI on September 19, 2026 at 05:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a release that incorporates the commit that cancels the isp1704 charger work before unregistering the power supply.
  • If a newer kernel is not immediately available, apply the patch from the provided git commit URL that adds the work cancellation logic.
  • Verify that the system is not removing the charger device while work may be scheduled, for example by suspending or preventing device hot‑plug events during critical operations.

Generated by OpenCVE AI on September 19, 2026 at 05:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: power: supply: isp1704_charger: cancel work on remove The USB notifier and initial VBUS detection can schedule isp->work. The remove path unregisters the notifier and power supply, but does not wait for queued or running work before tearing down the power supply state. Cancel the work after unregistering the notifier. Do this before unregistering the power supply. This issue was found by a static analysis tool.
Title power: supply: isp1704_charger: cancel work on remove
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:27.705Z

Reserved: 2026-09-11T19:38:34.810Z

Link: CVE-2026-90395

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:39.170

Modified: 2026-09-17T17:17:39.170

Link: CVE-2026-90395

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T08:15:13Z

Weaknesses