PT-2026-43746 · Linux+1 · Linux Kernel+1

·

CVE-2026-45879

·

Published

2026-05-27

·

Updated

2026-07-31

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A race condition exists in the bq25980 power supply driver. When the devm variant is used to request an IRQ before allocating or registering the power supply handle, the handle is deallocated before the interrupt handler during removal. This allows an interrupt to fire after the power supply handle is freed but before the IRQ handler is unregistered, leading to a use-after-free scenario when the IRQ handler calls the power supply changed() function. Additionally, during the probe() process, an interrupt could fire before the power supply handle is registered, resulting in the use of an uninitialized handle within power supply changed(). These issues can cause system crashes or silent memory corruption.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45879
SUSE-SU-2026:3130-1
SUSE-SU-2026:3166-1
USN-8492-1
USN-8492-2
USN-8492-3
USN-8492-4
USN-8492-5
USN-8497-1
USN-8498-1
USN-8499-1
USN-8575-1
USN-8575-2
USN-8575-3
USN-8576-1
USN-8576-2
USN-8606-1
USN-8607-1
USN-8609-1
USN-8610-1
USN-8619-1
USN-8620-1
USN-8620-2
USN-8620-3
USN-8620-4

Affected Products

Linuxmint
Linux Kernel