{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89469","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.709Z","datePublished":"2026-09-11T19:43:28.560Z","dateUpdated":"2026-09-14T12:00:06.392Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T12:00:06.392Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\npower: supply: lp8727: fix use-after-free in lp8727_release_irq()\n\nlp8727_isr_func(), the threaded IRQ handler, is the only caller that arms\npchg->work via schedule_delayed_work().  lp8727_release_irq() currently\ncancels the work before freeing the IRQ, so an IRQ delivered in between\ncan re-arm the work through the threaded handler.  After .remove returns\nthe devm layer frees pchg while lp8727_delayed_func() may still run and\ndereference it.\n\nFree the IRQ first so the threaded handler is quiesced and can no longer\nqueue work, then cancel the delayed work to drain the final generation.\n\nThis issue was found by an in-house static analysis tool."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The UAF is reached only when the onboard I2C LP8727 Micro/Mini USB charger is torn down locally (sysfs unbind, rmmod, or shutdown/reboot) so lp8727_delayed_func() runs after devm frees pchg; IRQs come from the chip INT GPIO, not from any network protocol.\nAC:L - The attacker controls both sides of the race: they start teardown while USB plug/unplug IRQs re-arm pchg->work after cancel_delayed_work_sync() and before free_irq(); the 270ms debounce then runs lp8727_delayed_func() on already-freed memory, so the UAF is retriable rather than layout-dependent.\nPR:N - On battery-powered devices with this USB charger IC, brief physical possession is enough to force power-off/reboot with no Linux account while charger IRQs fire during remove, as for the prior RT9455 teardown UAFs (CVE-2026-46270, CVE-2026-89465); CAP_SYS_ADMIN unbind is only an alternate path.\nUI:N - No victim action is required; the attacker performs teardown and any charging-port manipulation themselves, without the victim opening files, mounting filesystems, or approving prompts.\nS:U - The UAF corrupts kernel heap inside the same OS security authority; it is not a VM escape, IOMMU/DMA isolation bypass, or sandbox breakout.\nC:H - lp8727_delayed_func() recovers the freed lp8727_chg via container_of() and reads client, lock, pdata, and psy pointers, a classic kernel heap UAF that enables arbitrary disclosure via slab reuse.\nI:H - The same callback writes pchg fields, issues I2C SMBus writes, and calls power_supply_changed() on freed ac/usb/batt objects (changed flag and schedule_work), enabling heap-spray arbitrary writes and control-flow hijack.\nA:H - Use-after-free of pchg and the unregistered power_supply objects from workqueue context causes a kernel oops or panic even when the UAF is not fully exploited."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/power/supply/lp8727_charger.c"],"versions":[{"version":"d71fda01610269e3aaedd451f8d3e34cdf550036","lessThan":"1321a4e6247164312eabc6d07f88572da2ee308c","status":"affected","versionType":"git"},{"version":"d71fda01610269e3aaedd451f8d3e34cdf550036","lessThan":"dc1dc2837f8e53bde2f16d52a63f4142e21757f1","status":"affected","versionType":"git"},{"version":"d71fda01610269e3aaedd451f8d3e34cdf550036","lessThan":"035cc6bc4d412dd4302862e8f859b784fcd4653b","status":"affected","versionType":"git"},{"version":"d71fda01610269e3aaedd451f8d3e34cdf550036","lessThan":"6f0ce09d60a0e4fab6f9ebe8294750481f0c19dd","status":"affected","versionType":"git"},{"version":"d71fda01610269e3aaedd451f8d3e34cdf550036","lessThan":"80d4e40a85ba524e66c8c748aa7bb19eaf2f69df","status":"affected","versionType":"git"},{"version":"d71fda01610269e3aaedd451f8d3e34cdf550036","lessThan":"ab6b1ad710bed7931540733ce145493fece8ceef","status":"affected","versionType":"git"},{"version":"d71fda01610269e3aaedd451f8d3e34cdf550036","lessThan":"6ab3128292df67295de1b2a86f21d89cf6612a7e","status":"affected","versionType":"git"},{"version":"d71fda01610269e3aaedd451f8d3e34cdf550036","lessThan":"ceb6ac43b0f591722401922ceb958ce2616935e0","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/power/supply/lp8727_charger.c"],"versions":[{"version":"3.7","status":"affected"},{"version":"0","lessThan":"3.7","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.7","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.7","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.7","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.7","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.7","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.7","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.7","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.7","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/1321a4e6247164312eabc6d07f88572da2ee308c"},{"url":"https://git.kernel.org/stable/c/dc1dc2837f8e53bde2f16d52a63f4142e21757f1"},{"url":"https://git.kernel.org/stable/c/035cc6bc4d412dd4302862e8f859b784fcd4653b"},{"url":"https://git.kernel.org/stable/c/6f0ce09d60a0e4fab6f9ebe8294750481f0c19dd"},{"url":"https://git.kernel.org/stable/c/80d4e40a85ba524e66c8c748aa7bb19eaf2f69df"},{"url":"https://git.kernel.org/stable/c/ab6b1ad710bed7931540733ce145493fece8ceef"},{"url":"https://git.kernel.org/stable/c/6ab3128292df67295de1b2a86f21d89cf6612a7e"},{"url":"https://git.kernel.org/stable/c/ceb6ac43b0f591722401922ceb958ce2616935e0"}],"title":"power: supply: lp8727: fix use-after-free in lp8727_release_irq()","x_generator":{"engine":"bippy-1.2.0"}}}}