SB2026091723 - Use-after-free in Linux kernel iio chemical driver
Published: September 17, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-89938)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to compromise confidentiality, integrity, and availability.
The vulnerability exists due to a use-after-free in the Atlas sensor driver's IRQ work handling when a pending irq_work executes after device removal. A local user can cause pending IRQ work to execute after device removal to compromise confidentiality, integrity, and availability.
Exploitation requires an enabled IIO buffer.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/2071624c3d0f497ca91da78858e6f30d7112fea6
- https://git.kernel.org/stable/c/30b0d44c978bbc857bd68b71dab371805653de70
- https://git.kernel.org/stable/c/91e12b0fbd7047d02bf4ef4dbc491b9ef0159250
- https://git.kernel.org/stable/c/be61c8c6252671ecf1fee0ad90f87669e0be1e20
- https://git.kernel.org/stable/c/f64b437641b5a70c18bb0fd38da2b69d8926c871