{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89465","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.709Z","datePublished":"2026-09-11T19:43:25.950Z","dateUpdated":"2026-09-14T12:00:04.241Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T12:00:04.241Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\npower: supply: rt9455: quiesce delayed work before teardown\n\nThe threaded IRQ handler can queue pwr_rdy_work,\nmax_charging_time_work and batt_presence_work.  pwr_rdy_work and\nbatt_presence_work can also queue max_charging_time_work, while\nbatt_presence_work can requeue itself.\n\nrt9455_remove() cancels max_charging_time_work before\nbatt_presence_work.  The latter can therefore queue\nmax_charging_time_work after it has already been cancelled:\n\n  rt9455_remove()                   workqueue\n    cancel pwr_rdy_work\n    cancel max_charging_time_work\n                                      batt_presence_work queues\n                                        max_charging_time_work\n    cancel batt_presence_work\n    return\n    devres frees rt9455_info\n                                      max_charging_time_work dereferences\n                                        rt9455_info\n\nThe IRQ also remains registered until devres cleanup and can queue more\nwork after any of the cancellation calls.  If rt9455_hw_init() fails\nafter the IRQ has been requested, probe returns without cancelling work\nthat may already have been queued.  A pending callback can then access\nrt9455_info after it has been freed.\n\nRegister rt9455_cancel_all_delayed_works() through\ndevm_add_action_or_reset() right after devm_power_supply_register().\ndevres invokes the action in reverse registration order, after the\nmanaged IRQ has been freed and before rt9455_info is released, so the\ndelayed works are drained in both rt9455_remove() and the probe error\npath.  Cancel pwr_rdy_work and batt_presence_work before\nmax_charging_time_work because both can queue the latter.\n\nThis issue was found by an in-house static analysis tool."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The UAF is reached only when the I2C RT9455 charger is torn down locally (sysfs unbind, rmmod, or shutdown/reboot) so delayed work runs after rt9455_info is freed; charger IRQs come from the on-chip GPIO, not from any network protocol.\nAC:L - The attacker controls both sides of the race: they start teardown while USB plug/unplug IRQs or already-queued pwr_rdy_work/batt_presence_work (1s/60s, self-requeue) re-arm work after cancel; the delayed callbacks make the UAF window reliable, not layout-dependent.\nPR:N - On battery-powered devices with this IC, brief physical possession is enough to force power-off/reboot with no Linux account while charger IRQs fire during remove, as for the prior RT9455 teardown UAF (CVE-2026-46270); CAP_SYS_ADMIN unbind is only an alternate path.\nUI:N - No victim action is required; the attacker performs teardown and any charging-port manipulation themselves, without the victim opening files, mounting filesystems, or approving prompts.\nS:U - The UAF corrupts kernel heap inside the same kernel security authority and does not cross a VM, IOMMU, or sandbox boundary.\nC:H - Work callbacks container_of() a freed rt9455_info and then read client, regmap, and charger pointers, a classic use-after-free that yields arbitrary kernel reads after heap reuse.\nI:H - The same callbacks write through the freed object (queue_delayed_work, power_supply_changed, regmap_field_write), enabling heap-spray arbitrary writes and control-flow hijack.\nA:H - Use-after-free of driver private data from workqueue context causes a kernel oops or panic even when the UAF is not fully turned into a write primitive."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/power/supply/rt9455_charger.c"],"versions":[{"version":"e86d69dd786e94046b8f5be7df1b9a8226a40b2a","lessThan":"442c60c08ec23ac45da0a58877cab05e0a58f4ea","status":"affected","versionType":"git"},{"version":"e86d69dd786e94046b8f5be7df1b9a8226a40b2a","lessThan":"df67c7a2fff8414aa766b8cd5ffe11ec1ca27d02","status":"affected","versionType":"git"},{"version":"e86d69dd786e94046b8f5be7df1b9a8226a40b2a","lessThan":"1b9978433c61a9b46e48832a1ebceee1cf5c9eb4","status":"affected","versionType":"git"},{"version":"e86d69dd786e94046b8f5be7df1b9a8226a40b2a","lessThan":"7323e562f6961e4b7bce3225cde4ecbc78260deb","status":"affected","versionType":"git"},{"version":"e86d69dd786e94046b8f5be7df1b9a8226a40b2a","lessThan":"3e7a1ebc32fad5a558254a478efd401c17a24381","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/power/supply/rt9455_charger.c"],"versions":[{"version":"4.2","status":"affected"},{"version":"0","lessThan":"4.2","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/442c60c08ec23ac45da0a58877cab05e0a58f4ea"},{"url":"https://git.kernel.org/stable/c/df67c7a2fff8414aa766b8cd5ffe11ec1ca27d02"},{"url":"https://git.kernel.org/stable/c/1b9978433c61a9b46e48832a1ebceee1cf5c9eb4"},{"url":"https://git.kernel.org/stable/c/7323e562f6961e4b7bce3225cde4ecbc78260deb"},{"url":"https://git.kernel.org/stable/c/3e7a1ebc32fad5a558254a478efd401c17a24381"}],"title":"power: supply: rt9455: quiesce delayed work before teardown","x_generator":{"engine":"bippy-1.2.0"}}}}