Executive brief
A race condition vulnerability was identified in the Linux kernel's power supply driver for BQ25980 battery chargers. This flaw could allow a local attacker to cause a system crash or memory corruption during driver initialization or removal. The issue primarily affects system stability and availability.
Technical details
The vulnerability is a use-after-free (UAF) and race condition in the bq25980_charger driver. The root cause is the use of 'devm_' managed resource variants where the IRQ is requested before the power_supply handle is registered. Because 'devm_' deallocates resources in reverse order, the power_supply handle is freed before the IRQ handler is unregistered during driver removal. If an interrupt fires during this window, the handler calls power_supply_changed() with a pointer to freed memory. A similar race exists during probe() where an interrupt can fire before the handle is initialized. This can lead to kernel panics or silent memory corruption. The fix involves reordering the registration sequence to ensure the IRQ is requested only after the power supply handle is fully initialized.
Affected products
- Linux Linux kernel bq25980 charger driver
Timeline
- 2026-05-27: disclosed: Initial publication of the vulnerability advisory.
- 2026-05-27: advisory
References
- https://git.kernel.org/stable/c/03d1e4ee4e6aa6d2966e883e4ca0e5be73bf1b7c
- https://git.kernel.org/stable/c/0560a4b09c92e2ecaa883965cf6f9ca51c158ff9
- https://git.kernel.org/stable/c/0de95d29d847c6217b7d5845e24a71a4aee7b359
- https://git.kernel.org/stable/c/16875e3b7bc9e59bfa0acaf1e43f275a6f42a30f
- https://git.kernel.org/stable/c/4aeaf03c17260415c2fdd55992f9ad4188d5455a
- https://git.kernel.org/stable/c/5f0b1cb41906e86b64bf69f5ededb83b0d757c27
- https://git.kernel.org/stable/c/86f93dfb23f5bf4f285c4256a7e909d222f7de56