Junglewise Threat Intelligence

CVE-2026-46246: Linux Kernel use-after-free in pm8916_lbc power supply driver

CVE-2026-46246 · Severity: info · Published 2026-06-03

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's power supply driver for certain Qualcomm components. A technical flaw in how the system manages hardware interrupts could allow a race condition to occur when the driver is being removed or shut down. This could lead to a system crash or memory corruption, potentially impacting the stability and reliability of affected devices.

Technical details

A use-after-free vulnerability exists in the pm8916_lbc charger driver within the Linux kernel. The issue stems from an incorrect initialization order in the probe function where `devm_request_threaded_irq` is called before `devm_extcon_dev_allocate`. Because the `devm_` framework releases resources in reverse order of allocation, the `extcon` handle is freed before the IRQ handler is unregistered during driver removal. This creates a race condition where an interrupt firing after the handle is freed causes the handler to call `extcon_set_state_sync()` on deallocated memory. This typically results in a kernel panic or silent memory corruption. The fix involves reordering the calls so the IRQ is requested only after the extcon device is fully registered.

Affected products

  • Linux Linux Kernel f8d7a3d21160

Timeline

  • 2026-01-23: other: Patch authored
  • 2026-06-03: disclosed: CVE published

References

Related threats