Use-after-free in Linux kernel - CVE-2026-90026
Published: September 16, 2026
Vulnerability details
The vulnerability allows a local user to compromise confidentiality, integrity, and availability.
The vulnerability exists due to a use-after-free in the Qualcomm PMIC Type-C PD PHY driver's reset_work handling when pending reset_work executes after device removal frees its associated structure. A local user can trigger the race condition to compromise confidentiality, integrity, and availability.
The race requires the IRQ handler to schedule reset_work immediately before IRQs are disabled.
Affected software
How to mitigate CVE-2026-90026
External References
- https://git.kernel.org/stable/c/0b69b166852dbf1f9532b22bd49f502e5970eb95
- https://git.kernel.org/stable/c/52d556f08547733948cc40b8b11e6b68dccee7b2
- https://git.kernel.org/stable/c/7b0df6efd143f8085bdb68778a013a46f1349913
- https://git.kernel.org/stable/c/b9a7eed472edbfa8dec0fdeafd5e796550a8a8b7
- https://git.kernel.org/stable/c/d4e00a1eb39174e25ef759b8fb1111bba8e87b1e