Junglewise Threat Intelligence

CVE-2026-90394: Linux kernel sc2731_charger use-after-free on driver removal

CVE-2026-90394 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's SC2731 charger driver fails to properly cancel background work tasks before releasing driver memory during device removal. This can cause the kernel to access freed memory when queued or running work attempts to execute after the driver is unloaded, potentially leading to kernel crashes or undefined behavior on systems with this charger hardware.

Technical details

The vulnerability is a use-after-free condition in the SC2731 charger power supply driver. The USB notifier and initial charger detection logic schedule work on info->work, but the remove path unregisters the notifier without canceling queued or running work before the devm-allocated driver data is released. This leaves dangling work items that may reference freed memory. The fix adds platform_set_drvdata() in the probe path and cancel_work_sync() in the remove path to ensure all queued work is canceled before device memory is deallocated. The issue was discovered via static analysis and affects any kernel version containing the sc2731_charger driver with the vulnerable probe/remove sequence.

Affected products

  • Linux Linux kernel all versions with sc2731_charger driver

Timeline

  • 2026-09-17: disclosed: CVE-2026-90394 published
  • 2026-09-14: patched: Fix committed upstream by Greg Kroah-Hartman

References

Related threats