Use-after-free in Linux kernel - CVE-2026-89465
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to access freed rt9455_info memory.
The vulnerability exists due to improper delayed-work cancellation in RT9455 charger driver teardown handling when delayed work is pending during device removal or probe error cleanup. A local user can race delayed work with teardown to access freed rt9455_info memory.
The threaded IRQ handler can queue delayed work, and batt_presence_work can requeue itself or queue max_charging_time_work.