Executive brief
A vulnerability was identified in the Linux kernel's battery driver for certain mobile devices. A race condition during system shutdown or driver removal could cause the system to crash or experience memory corruption. This occurs because the system may attempt to process a battery-related notification after the necessary software components have already been shut down.
Technical details
A use-after-free vulnerability exists in the cpcap-battery driver (drivers/power/supply/cpcap-battery.c) due to improper resource management using the devm_ framework. The driver requested interrupts before registering the power_supply handle. Because devm_ deallocates resources in reverse order, the power_supply handle is freed before the interrupt handler is unregistered during driver removal. This creates a race condition where an interrupt firing after the handle is freed causes power_supply_changed() to be called with a stale pointer. A similar race exists during probe() where an interrupt could fire before the handle is initialized. The fix reorders the initialization to ensure the IRQ is requested only after the power_supply handle is fully registered.
Affected products
- Linux Linux kernel All versions prior to the fix in the cpcap-battery driver
Timeline
- 2025-12-20: other: Patch authored
- 2026-05-27: advisory: CVE-2026-45885 published
References
- https://git.kernel.org/stable/c/2841bbb5a35c4449c0a0458e8e476b2a62f95147
- https://git.kernel.org/stable/c/2ce2334be155bd8bad6377e99984246ce4dbd08c
- https://git.kernel.org/stable/c/3ff75cba1c98349a23a8f9333981deba1972cc11
- https://git.kernel.org/stable/c/642f33e34b969eedec334738fd5df95d2dc42742
- https://git.kernel.org/stable/c/c549dd3de4b3f6e726d1b8386d40ccf7d3abdbe4
- https://git.kernel.org/stable/c/cbb9b07f88a9ef6518934c41eb3e8cf840d657d5
- https://git.kernel.org/stable/c/e261be6f18929f2397cd54cd583a2df624c129c1