power: supply: bq256xx: drain usb_work before freeing the charger
Published Sep 11, 2026
5.5
MEDIUMCVSS 3.1
EPSS 0.17%
Description
The USB-PHY notifier queues usb_work, whose handler calls power_supply_changed(bq->charger). The reset devm action only unregisters the notifier and was registered before the power supplies, so devm frees bq->charger on unwind before the action runs; a usb_work still queued can then dereference it.
Register the reset action after the power supplies, so it unregisters the notifiers and drains usb_work before the supplies are released. Initialize usb_work and obtain the PHY references before registering the notifiers, so the worker cannot run before the supplies exist.
Found by static analysis.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.12StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.12
- Version 5.15.221StatusunaffectedConstraints<=5.15.*
- Version 6.1.188StatusunaffectedConstraints<=6.1.*
- Version 6.12.109StatusunaffectedConstraints<=6.12.*
- Version 6.18.50StatusunaffectedConstraints<=6.18.*
- Version 6.6.157StatusunaffectedConstraints<=6.6.*
- Version 7.2.4StatusunaffectedConstraints<=7.2.*
- Version 7.3-rc1StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
No data.
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 10
kernel-rt
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Not affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 10 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (12)
- https://access.redhat.com/security/cve/CVE-2026-89474 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2532371 Issue Tracking
- https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89474.mbox
- https://git.kernel.org/stable/c/2cfb59dc9df8b5ebdd95e3d874a7f4690cee2bc8
- https://git.kernel.org/stable/c/2dd6cd823777bea6d9a880a12a92a73ec76aee0b
- https://git.kernel.org/stable/c/9a467bd1e6811011026ad4c8de701b940d88a00c
- https://git.kernel.org/stable/c/9dcfdf6c598301b278f0b3490eb2bf4f600524e2
- https://git.kernel.org/stable/c/9e1aba34df9a87d53460888e05718717c0f69343
- https://git.kernel.org/stable/c/c8addb842ae8dcf69c15fc976e33e3bd538a41d7
- https://git.kernel.org/stable/c/fd08d4dbbec07a44f01b0ddb041912be0dc88f8c
- https://nvd.nist.gov/vuln/detail/CVE-2026-89474
- https://www.cve.org/CVERecord?id=CVE-2026-89474
Change history (0)
No recorded changes yet.