Junglewise Threat Intelligence

CVE-2026-45885: Linux Kernel use-after-free in cpcap-battery driver

CVE-2026-45885 · Severity: info · CVSS 5.5 · Published 2026-05-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's battery driver for certain mobile devices. A race condition during system shutdown or driver removal could cause the system to crash or experience memory corruption. This occurs because the system may attempt to process a battery-related notification after the necessary software components have already been shut down.

Technical details

A use-after-free vulnerability exists in the cpcap-battery driver (drivers/power/supply/cpcap-battery.c) due to improper resource management using the devm_ framework. The driver requested interrupts before registering the power_supply handle. Because devm_ deallocates resources in reverse order, the power_supply handle is freed before the interrupt handler is unregistered during driver removal. This creates a race condition where an interrupt firing after the handle is freed causes power_supply_changed() to be called with a stale pointer. A similar race exists during probe() where an interrupt could fire before the handle is initialized. The fix reorders the initialization to ensure the IRQ is requested only after the power_supply handle is fully registered.

Affected products

  • Linux Linux kernel All versions prior to the fix in the cpcap-battery driver

Timeline

  • 2025-12-20: other: Patch authored
  • 2026-05-27: advisory: CVE-2026-45885 published

References

Related threats