Use-after-free in Linux kernel - CVE-2026-89472
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to trigger a use-after-free condition.
The vulnerability exists due to use-after-free in charger-manager regulator handle management when handling a concurrent write to the externally_control sysfs attribute during device teardown. A local user can write to the externally_control sysfs attribute while charging is enabled to trigger a use-after-free condition.
The sysfs attribute can also be exposed before regulator acquisition completes during probing.