Executive brief
The Linux kernel's character LCD display driver (charlcd) contains a defect in its initialization and registration flow that can lead to a system crash or code execution. When the driver's registration fails, a delayed work queue (backlight task) continues to reference memory that has been freed, resulting in a use-after-free condition. This vulnerability affects systems using character LCD displays with backlight flash support enabled.
Technical details
The vulnerability is a use-after-free bug (CWE-416) in the charlcd driver's auxdisplay subsystem. When CONFIG_CHARLCD_BL_FLASH is enabled, charlcd_init() schedules a delayed work queue (bl_work) before charlcd_register() attempts to register the device via misc_register(). If misc_register() fails, the caller frees the charlcd object while the delayed work still holds a pointer to it. The fix adds a new charlcd_deinit() function that properly cancels the delayed work and turns off the backlight before the object is freed. This function is called both during registration rollback and during normal unregistration. No network access or authentication is required; the vulnerability only manifests when device registration fails during driver probe on systems with CONFIG_CHARLCD_BL_FLASH enabled.
Affected products
- Linux Linux kernel Affected versions depend on kernel series; patch applied across stable branches linux-4.19.y through linux-7.2.y and current development
Timeline
- 2026-09-11: disclosed: Published in NVD
- 2026-09-14: patched: Fix committed to Linux kernel stable trees by Greg Kroah-Hartman