Junglewise Threat Intelligence

CVE-2026-45946: Linux kernel use-after-free in ab8500 power supply driver

CVE-2026-45946 · Severity: info · CVSS 5.5 · Published 2026-05-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's power supply driver for certain hardware components. A race condition during system startup or shutdown could cause the system to crash or experience memory corruption. This occurs because the system may attempt to process power-related signals using memory that has already been cleared or has not yet been set up.

Technical details

A use-after-free (UAF) vulnerability exists in the ab8500_charger driver within the Linux kernel power supply subsystem. The issue stems from the incorrect ordering of resource allocation using the devm_ framework. Specifically, the driver requested IRQs before registering the power_supply handle. Because devm_ releases resources in reverse order of allocation, the power_supply handle is freed before the IRQ handler is unregistered during driver removal. This creates a race condition where an interrupt firing after the handle is freed causes power_supply_changed() to be called with a stale pointer. A similar race exists during probe() where an interrupt may fire before the handle is initialized. The fix involves reordering the probe sequence to ensure IRQs are requested only after the power_supply handle is fully registered.

Affected products

  • Linux Linux kernel versions including 1c1f13a006ed

Timeline

  • 2025-12-20: other: Patch authored
  • 2026-05-27: advisory: CVE published

References