{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89938","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.776Z","datePublished":"2026-09-16T10:32:27.012Z","dateUpdated":"2026-09-16T14:40:24.952Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-16T14:40:24.952Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF\n\nThe atlas driver requests its hardware data-ready IRQ with\ndevm_request_threaded_irq(); its threaded handler queues an irq_work,\natlas_work_handler(), that calls iio_trigger_poll(data->trig).\n\nThe IRQ is devm-managed, so free_irq() runs from the devres unwind after\natlas_remove() returns without flushing that irq_work.  Once a buffer is\nenabled, conversion-complete IRQs keep firing and queueing it; a pending\nirq_work can therefore run after the unwind has freed atlas_data/indio_dev\nand the trigger, when atlas_work_handler() derives the atlas_data pointer\nvia container_of() and dereferences data->trig, a use-after-free.\n\nCall iio_trigger_poll_nested() directly from the threaded handler instead\nof bouncing through irq_work.  free_irq() then drains the threaded handler,\nclosing the window; other iio drivers with a threaded data-ready IRQ do the\nsame (e.g. bmi270).\n\nThis issue was found by an in-house static analysis tool."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The use-after-free is reached from local IIO sysfs/chardev buffer enable on the Atlas I2C chemical sensor plus driver teardown (sysfs unbind, rmmod, or parent adapter removal). There is no network, Bluetooth, or remote-protocol path into atlas_interrupt_handler or atlas_work_handler.\nAC:L - With the IIO buffer enabled, conversion-complete IRQs keep queueing irq_work every 450-650ms. atlas_remove() never calls irq_work_sync(), so pending work runs after the synchronous devres unwind frees atlas_data. The attacker controls buffer enable and bind/unbind retries; on PREEMPT_RT or CPUs without an irq_work IPI the window is milliseconds.\nPR:L - IIO buffer/enable is mode 0644 with no capability check, and on industrial/IoT water-quality systems that ship Atlas OEM SM sensors those nodes are commonly group-accessible to monitoring services. Per driver-removal UAF scoring, an unprivileged local user can drive the IRQ/irq_work side while teardown proceeds; init-namespace root is not required.\nUI:N - The attacker enables the IIO buffer themselves and coordinates driver unbind or module teardown; no separate victim action such as plugging hardware or mounting a filesystem is required.\nS:U - The use-after-free corrupts kernel heap objects (atlas_data and the IIO trigger) in the host kernel's own security authority. This is a standard local kernel privilege-escalation path, not a VM, IOMMU, or sandbox boundary crossing.\nC:H - atlas_work_handler() recovers freed atlas_data via container_of() and dereferences data->trig. A use-after-free of that sprayable driver-private object yields an arbitrary kernel read primitive, including via iio_trigger_poll() walking attacker-controlled trigger state.\nI:H - After spraying the freed atlas_data, data->trig is attacker-controlled, so iio_trigger_poll() performs atomic updates and generic_handle_irq() on attacker-chosen IRQ numbers. That is an arbitrary kernel write and control-flow hijack primitive, consistent with use-after-free scoring.\nA:H - The pending irq_work running against freed atlas_data and the IIO trigger causes a kernel oops or panic (KASAN use-after-free or a wild dereference of data->trig), so availability impact is high even without a full exploit."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/iio/chemical/atlas-sensor.c"],"versions":[{"version":"7103b99b031cb0ff6979331757bfc4893f37ae9e","lessThan":"f64b437641b5a70c18bb0fd38da2b69d8926c871","status":"affected","versionType":"git"},{"version":"7103b99b031cb0ff6979331757bfc4893f37ae9e","lessThan":"91e12b0fbd7047d02bf4ef4dbc491b9ef0159250","status":"affected","versionType":"git"},{"version":"7103b99b031cb0ff6979331757bfc4893f37ae9e","lessThan":"2071624c3d0f497ca91da78858e6f30d7112fea6","status":"affected","versionType":"git"},{"version":"7103b99b031cb0ff6979331757bfc4893f37ae9e","lessThan":"30b0d44c978bbc857bd68b71dab371805653de70","status":"affected","versionType":"git"},{"version":"7103b99b031cb0ff6979331757bfc4893f37ae9e","lessThan":"be61c8c6252671ecf1fee0ad90f87669e0be1e20","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/iio/chemical/atlas-sensor.c"],"versions":[{"version":"4.8","status":"affected"},{"version":"0","lessThan":"4.8","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.51","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.5","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"6.18.51"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"7.2.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/f64b437641b5a70c18bb0fd38da2b69d8926c871"},{"url":"https://git.kernel.org/stable/c/91e12b0fbd7047d02bf4ef4dbc491b9ef0159250"},{"url":"https://git.kernel.org/stable/c/2071624c3d0f497ca91da78858e6f30d7112fea6"},{"url":"https://git.kernel.org/stable/c/30b0d44c978bbc857bd68b71dab371805653de70"},{"url":"https://git.kernel.org/stable/c/be61c8c6252671ecf1fee0ad90f87669e0be1e20"}],"title":"iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF","x_generator":{"engine":"bippy-1.2.0"}}}}