PT-2026-93668 · Linux · Linux Kernel

CVE-2026-90027

·

Published

2026-09-16

·

Updated

2026-09-24

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A race condition exists in the qcom-pmic-typec driver where cc debounce dwork is queued via set cc() and start toggling() callbacks. Because port stop() returns before the TCPM kthread worker is destroyed by tcpm unregister port(), flushing the worker can trigger a callback that queues delayed work after port stop() has finished. This allows the delayed work to execute after devres has already freed pmic typec port, potentially leading to a use-after-free scenario.
Recommendations Use disable delayed work sync() in port stop() to cancel pending instances and prevent TCPM callbacks from queueing new work.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-101666
CVE-2026-90027
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel