Executive brief
A vulnerability was identified in the Linux kernel's act8945a charger driver that could lead to a system crash or memory corruption. The issue occurs due to a race condition during the initialization or removal of the power supply component, where an interrupt might trigger while the system is in an unstable state. This could allow a local attacker or a malfunctioning hardware component to disrupt system operations or potentially gain unauthorized access to memory.
Technical details
A use-after-free vulnerability exists in the act8945a charger driver within the Linux kernel's power supply subsystem. The root cause is the incorrect ordering of resource allocation using the `devm_` framework; specifically, the IRQ is requested before the `power_supply` handle is registered. Because `devm_` deallocates resources in reverse order, the `power_supply` handle is freed before the IRQ handler is unregistered during driver removal. This creates a race condition where an interrupt firing after the handle is freed results in `power_supply_changed()` being called with a stale pointer. A similar race exists during `probe()` where an interrupt can fire before the handle is initialized. The fix reorders the operations to ensure the IRQ is requested only after the power supply handle is fully registered.
Affected products
- Linux Linux Kernel act8945a charger driver
Timeline
- 2025-12-20: other: Patch authored
- 2026-05-27: disclosed: CVE published
References
- https://git.kernel.org/stable/c/0768e8525a46df103647ca5059b32320d7fd17e4
- https://git.kernel.org/stable/c/3291c51d4684d048dd2eb91b5b65fcfdaf72141f
- https://git.kernel.org/stable/c/697bb5dc0cb4791e244f3970b067bc1ef33be9d9
- https://git.kernel.org/stable/c/76a42ba547a9b2e2337894f67a4d9247445007d5
- https://git.kernel.org/stable/c/83c1bd466c514cb24ca6ef347c5aac76a13c4e1e
- https://git.kernel.org/stable/c/d023ef9f748b2090f7a9dbdd5c622b6ad99088ea
- https://git.kernel.org/stable/c/f27eb76def5c07e4d7cc468b40741f19dafc83ce