Junglewise Threat Intelligence

CVE-2026-45938: Linux Kernel pm8916_lbc use-after-free in power_supply_changed

CVE-2026-45938 · Severity: info · CVSS 5.5 · Published 2026-05-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's power supply driver for certain Qualcomm chipsets. The issue involves a race condition that can occur when the driver is being initialized or removed, potentially leading to a system crash or memory corruption. This could impact the stability and reliability of devices using this specific hardware component.

Technical details

A use-after-free vulnerability exists in the pm8916_lbc power supply driver within the Linux kernel. The root cause is the use of devm_ functions in an incorrect order during the probe process: the IRQ is requested before the power_supply handle is registered. Because devm_ resources are released in reverse order of allocation, the power_supply handle is freed before the IRQ handler is unregistered during driver removal. This creates a race condition where an interrupt firing after the handle is freed causes power_supply_changed() to access invalid memory. Additionally, an interrupt firing during probe before registration can lead to an uninitialized pointer access. The fix reorders the probe sequence to ensure the IRQ is requested only after the power supply handle is fully registered.

Affected products

  • Linux Linux Kernel pm8916_lbc driver

Timeline

  • 2025-12-20: other: Patch authored
  • 2026-05-27: disclosed: CVE published

References

Related threats