PT-2026-93668 · Linux · Linux Kernel
CVE-2026-90027
·
Published
2026-09-16
·
Updated
2026-09-24
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A race condition exists in the
qcom-pmic-typec driver where cc debounce dwork is queued via set cc() and start toggling() callbacks. Because port stop() returns before the TCPM kthread worker is destroyed by tcpm unregister port(), flushing the worker can trigger a callback that queues delayed work after port stop() has finished. This allows the delayed work to execute after devres has already freed pmic typec port, potentially leading to a use-after-free scenario.Recommendations
Use
disable delayed work sync() in port stop() to cancel pending instances and prevent TCPM callbacks from queueing new work.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel