CVE-2026-90394

Source
https://cve.org/CVERecord?id=CVE-2026-90394
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90394.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90394
Downstream
Published
2026-09-17T16:09:27Z
Modified
2026-09-18T03:48:38Z
Summary
power: supply: sc2731_charger: cancel work on remove
Details

In the Linux kernel, the following vulnerability has been resolved:

power: supply: sc2731_charger: cancel work on remove

The USB notifier and initial charger detection can schedule info->work. The remove path unregisters the notifier, but does not cancel queued or running work before the devm-allocated driver data is released.

Set the platform drvdata used by remove, then cancel the work after unregistering the notifier.

This issue was found by a static analysis tool.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90394.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
8ac1091ed18b4a6cb0dc2cd5653f080736f89392
Fixed
bb74a5ab30963022981381ea6aee176fd0c7957c
Fixed
232e9e946b496e4706e2f34ce4a617460d8ae713
Fixed
05c188addc6d1af51e28496e95096f4df9a000e9
Fixed
972d88069050d0272b776145b824198b8f899dce
Fixed
c6df6e0c099086bc553d44410015cc81795070e6
Fixed
d5266b4c5c77152e386a3a2d9d5244b3b6cbd57a
Fixed
aab9d81a415c6653b44b057695ebfbba34dc9556
Fixed
dfc859bb8d332c525872f1a44028137724fa1998

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90394.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.0.0
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90394.json"