Executive brief
The isp1704_charger driver in the Linux kernel contains a race condition where scheduled work items are not properly cancelled during device removal. This could potentially lead to use-after-free memory access or kernel crashes if cleanup completes while work is still pending. The issue affects all Linux kernel versions that include this driver.
Technical details
The vulnerability is a use-after-free/race condition in the isp1704_charger power supply driver. The USB notifier and VBUS detection logic can schedule work via isp->work, but the device removal path unregisters the notifier and power supply without waiting for or cancelling pending work. This leaves queued or running work that may attempt to access freed power supply structures. The fix adds cancel_work_sync() after unregistering the notifier but before unregistering the power supply. No network attack vector exists; this requires direct access to the platform device removal mechanism. The issue was discovered via static analysis and a patch has been released.
Affected products
- Linux Linux Kernel all versions with isp1704_charger driver
Timeline
- 2026-09-17: disclosed
- 2026-07-31: patched