{"id":"CVE-2026-89472","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-89472","summary":"power: supply: charger-manager: register regulators before exposing sysfs","details":"In the Linux kernel, the following vulnerability has been resolved:\n\npower: supply: charger-manager: register regulators before exposing sysfs\n\ncharger_manager_remove() and the err_reg_extcon probe error path free each\ncharger regulator with regulator_put() before tearing down the power_supply\nsysfs entries (power_supply_unregister()). charger_manager_remove() also\ncalls try_charger_enable(cm, false) after the regulator_put() loop. A\nconcurrent write to a charger's externally_control sysfs attribute that\nlands between regulator_put() and power_supply_unregister() can run\ncharger_externally_control_store() and call try_charger_enable(), which,\nwhen charging is enabled, dereferences the already-freed consumer handle.\nWhen charging is enabled, try_charger_enable(cm, false) in .remove() also\ndereferences the freed handles directly. Both leave use-after-free windows.\nSymmetrically, probe registers the sysfs entries (power_supply_register)\nbefore acquiring the regulators (regulator_get, inside\ncharger_manager_register_extcon), so userspace can reach externally_control\nbefore the regulators are available.\n\nSplit charger_manager_register_extcon() on the sync/async boundary:\ncharger_manager_get_regulators() (regulator_get only, no async producer)\nnow runs before power_supply_register() so sysfs is not live before\nregulators are available, and charger_manager_register_extcon() keeps only\nthe extcon notifier/work setup, still after power_supply_register() so a\npower_supply_register() failure cannot reach extcon setup. This keeps the\nsysfs setup/teardown ordering symmetric without introducing an asynchronous\nproducer on the earlier probe-error path.\n\nMove power_supply_unregister() and try_charger_enable(cm, false) ahead of\nthe regulator_put() loop on both teardown paths, and adjust err_reg_extcon\n(power_supply_unregister() then fall through err_regulator for\nregulator_put(); get_regulators self-rolls back on its own failure).\n\nThis does not address the separate extcon-notifier-driven deref of the same\nhandles, which needs its own synchronization design.\n\nFound by an in-house static analysis tool.","published":"2026-09-11T19:43:30.536Z","modified":"2026-09-14T03:46:10.835127409Z","cvss":{"score":7.8,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Linux","name":"Kernel","fixedVersion":"6.12.109"}],"fix":null,"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/6d532582ff3c420598f02945b13184c738cc1581"},{"type":"WEB","url":"https://git.kernel.org/stable/c/86e4fa65368f3bbb506dddba8c9eedc75bd603b2"},{"type":"WEB","url":"https://git.kernel.org/stable/c/af3ce383ba0d0d48957a22ac7058ff5698775898"},{"type":"WEB","url":"https://git.kernel.org/stable/c/c57cb36f76eb7ced45f57af1a890d8f3a6d76342"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89472.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89472"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-14T03:46:10.835127409Z"}}