Executive brief
A vulnerability was identified in the Linux kernel's bq256xx charger driver, which manages power supply and battery charging for certain hardware components. A race condition during the driver's initialization or removal process can cause the system to attempt to use memory that has already been freed or has not yet been initialized. This can lead to unpredictable system behavior, including silent memory corruption or a complete system crash (denial of service).
Technical details
A use-after-free (UAF) and uninitialized pointer vulnerability exists in the bq256xx charger driver (drivers/power/supply/bq256xx_charger.c). The root cause is the incorrect use of the 'devm_' managed resource framework, where the IRQ handler is requested before the power_supply handle is registered. Because 'devm_' releases resources in reverse allocation order, the power_supply handle is deallocated before the IRQ handler is unregistered during driver removal. This creates a race condition where an interrupt firing during removal calls power_supply_changed() with a freed handle. Additionally, during probe(), an interrupt can fire before the handle is initialized. Attackers with local access could potentially trigger these conditions to cause memory corruption or a kernel panic. The fix involves reordering the probe sequence to ensure the power_supply handle is registered before the IRQ is requested.
Affected products
- Linux Linux Kernel bq256xx charger driver
Timeline
- 2025-12-20: other: Patch authored
- 2026-01-12: patched: Patch committed to maintainer tree
- 2026-05-27: advisory: NVD publication date
References
- https://git.kernel.org/stable/c/4b6fb0b6124f558131e502e3ffd03e6583b3ace6
- https://git.kernel.org/stable/c/74b5a88318db97d51bb40f774736553c2acd1514
- https://git.kernel.org/stable/c/8005843369723d9c8975b7c4202d1b85d6125302
- https://git.kernel.org/stable/c/81d3688c9a2158329391e08f2d0b8ba204216044
- https://git.kernel.org/stable/c/83c27fdd696ac13d023ef7a0345301be93209c53
- https://git.kernel.org/stable/c/8796910131a32ff29275052df768ef022929a394
- https://git.kernel.org/stable/c/cb5c743936edcebc51880eeb6bf04979b5c9438b