CVE-2026-89938

Source
https://cve.org/CVERecord?id=CVE-2026-89938
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89938.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89938
Downstream
Published
2026-09-16T10:32:27Z
Modified
2026-09-17T03:47:26Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF
Details

In the Linux kernel, the following vulnerability has been resolved:

iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF

The atlas driver requests its hardware data-ready IRQ with devm_request_threaded_irq(); its threaded handler queues an irq_work, atlas_work_handler(), that calls iio_trigger_poll(data->trig).

The IRQ is devm-managed, so free_irq() runs from the devres unwind after atlas_remove() returns without flushing that irq_work. Once a buffer is enabled, conversion-complete IRQs keep firing and queueing it; a pending irq_work can therefore run after the unwind has freed atlas_data/indio_dev and the trigger, when atlas_work_handler() derives the atlas_data pointer via container_of() and dereferences data->trig, a use-after-free.

Call iio_trigger_poll_nested() directly from the threaded handler instead of bouncing through irq_work. free_irq() then drains the threaded handler, closing the window; other iio drivers with a threaded data-ready IRQ do the same (e.g. bmi270).

This issue was found by an in-house static analysis tool.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89938.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
7103b99b031cb0ff6979331757bfc4893f37ae9e
Fixed
f64b437641b5a70c18bb0fd38da2b69d8926c871
Fixed
91e12b0fbd7047d02bf4ef4dbc491b9ef0159250
Fixed
2071624c3d0f497ca91da78858e6f30d7112fea6
Fixed
30b0d44c978bbc857bd68b71dab371805653de70
Fixed
be61c8c6252671ecf1fee0ad90f87669e0be1e20

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89938.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.8.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.51
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89938.json"