SB20260918272 - Use-after-free in Linux kernel power supply driver
Published: September 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-90394)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to access freed driver data.
The vulnerability exists due to use-after-free in the sc2731_charger driver's remove path when queued or running work executes after driver data is released. A local user can cause the driver to be removed while work remains queued or running to access freed driver data.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/05c188addc6d1af51e28496e95096f4df9a000e9
- https://git.kernel.org/stable/c/232e9e946b496e4706e2f34ce4a617460d8ae713
- https://git.kernel.org/stable/c/972d88069050d0272b776145b824198b8f899dce
- https://git.kernel.org/stable/c/aab9d81a415c6653b44b057695ebfbba34dc9556
- https://git.kernel.org/stable/c/bb74a5ab30963022981381ea6aee176fd0c7957c
- https://git.kernel.org/stable/c/c6df6e0c099086bc553d44410015cc81795070e6
- https://git.kernel.org/stable/c/d5266b4c5c77152e386a3a2d9d5244b3b6cbd57a
- https://git.kernel.org/stable/c/dfc859bb8d332c525872f1a44028137724fa1998