Description
In the Linux kernel, the following vulnerability has been resolved:

platform/chrome: cros_ec_debugfs: Unregister panic notifier

cros_ec_debugfs_probe() registers notifier_panic with the EC panic
notifier chain. The remove path tears down debugfs and the console log,
but leaves the notifier registered. A later panic notification can call
back into the removed instance and queue work that accesses released
data.

Unregister the panic notifier before tearing down the debugfs and
console log state.

This issue was found by a static analysis tool.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary code execution via use‑after‑free on kernel panic
Action: Immediate Patch
AI Analysis

Impact

During module removal the debugfs entries and console log are torn down, but the notifier remains registered. If a kernel panic occurs after this removal, the notifier's callback will run against data that has already been freed. Based on the description, it is inferred that this freed data access could lead to arbitrary code execution or a system crash. This use‑after‑free flaw (CWE‑416) could compromise confidentiality, integrity, and availability of the host.

Affected Systems

Vendors are Linux kernel maintainers. It is inferred that the vulnerability affects any Linux kernel build that includes the cros_ec_debugfs module, such as Chrome OS releases that use the Chrome OS EC debug filesystem. Specific version numbers are not listed in the advisory; operators should verify if their kernel contains this module and the problematic init/exit logic.

Risk and Exploitability

The EPSS score is the lowest band (<1%) and the flaw is not cataloged in CISA KEV, indicating a low likelihood of widespread exploitation. Nonetheless, the impact of executing code during a kernel panic is severe, giving an attacker potential root‑level control, especially if they can trigger a panic (e.g., via malformed EC commands). The likely attack vector is local and requires the ability to cause a panic in the targeted system.

Generated by OpenCVE AI on September 19, 2026 at 14:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel patch that unregisters the panic notifier before tearing down the debugfs and console log.
  • Upgrade to a Linux kernel version that includes this fix if not already available.
  • If an immediate patch is unavailable, disable or remove the cros_ec_debugfs module and any associated debugfs entries from the system to prevent the dangling notifier from executing during a panic.

Generated by OpenCVE AI on September 19, 2026 at 14:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: platform/chrome: cros_ec_debugfs: Unregister panic notifier cros_ec_debugfs_probe() registers notifier_panic with the EC panic notifier chain. The remove path tears down debugfs and the console log, but leaves the notifier registered. A later panic notification can call back into the removed instance and queue work that accesses released data. Unregister the panic notifier before tearing down the debugfs and console log state. This issue was found by a static analysis tool.
Title platform/chrome: cros_ec_debugfs: Unregister panic notifier
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:33.472Z

Reserved: 2026-09-11T19:38:34.811Z

Link: CVE-2026-90404

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:40.237

Modified: 2026-09-17T17:17:40.237

Link: CVE-2026-90404

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T14:15:17Z

Weaknesses