CVE-2026-89797
CVE CVE-2026-89797EUVD EUVD-2026-80397Published 2026-09-16T10:30:28.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: power: supply: ab8500_fg: fix use-after-free on remove ab8500_fg_remove() destroys the driver workqueue while the threaded interrupt handlers are still armed; they are devm-managed and freed only after ->remove() returns, so a handler that fires in that window queues work on the freed workqueue. Tear the workqueue down through devm instead, registering its cleanup after the power supply and before the interrupt requests. devm then frees the interrupts first, so the handlers can no longer queue work, before disabling the delayed and plain work items and destroying the workqueue. Disabling the items, rather than cancelling them, keeps them disabled so no producer (including the power-supply external_power_changed callback) can requeue them. Found by an in-house static analysis tool.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 13151631b5bd06a1511353bb221079bbd76606c3 <c660c017dec1fd7cd88e1103c5ae1aae6ce636bf; patch: 7.3-rc1; 13151631b5bd06a1511353bb221079bbd76606c3 <013731074ab6a8d11ec209eee64c5b2656954479; patch: 0; 3.4; patch: 6.18.51; patch: 7.2.5; 13151631b5bd06a1511353bb221079bbd76606c3 <75b1e88d34254f4fb7753345e21bfee47abddd7f
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.