CVE-2026-53308 Details
Description
In the Linux kernel, the following vulnerability has been resolved: power: supply: max77705: Free allocated workqueue and fix removal order Use devm interface for allocating workqueue to fix two bugs at the same time: 1. Driver leaks the memory on remove(), because the workqueue is not destroyed. 2. Driver allocates workqueue and then registers interrupt handlers with devm interface. This means that probe error paths will not use a reversed order, but first destroy the workqueue and then, via devm release handlers, free the interrupt. The interrupt handler schedules work on this exact workqueue, thus if interrupt is hit in this short time window - after destroying workqueue, but before devm() frees the interrupt - the schedulled work will lead to use of freed memory. Change is not equivalent in the workqueue itself: use non-legacy API which does not set (__WQ_LEGACY | WQ_MEM_RECLAIM). The workqueue is used to update power supply (power_supply_changed()) status, thus there is no point to run it for memory reclaim. Note that dev_name() is not directly used in second argument to prevent possible unlikely parsing any "%" character in device name as format.
A vulnerability has been identified in the Linux kernel's power supply driver for the Maxim 77705 charger. The issue arises from improper management of a workqueue, leading to a memory leak when the driver is removed. The workqueue is not properly destroyed, causing allocated memory to be unreleased. Additionally, the driver registers interrupt handlers using a device-managed interface after allocating the workqueue. This sequence can create a timing issue where an interrupt is processed after the workqueue is destroyed but before the interrupt handler is freed, resulting in the use of freed memory. The vulnerability affects the Linux kernel stable tree.
The vulnerability has been addressed by modifying the driver to use the device-managed interface for workqueue allocation, ensuring proper cleanup and preventing memory leaks. Users should upgrade to the patched version of the driver.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/1e668baadefb16e81269dbfebf3ffc2672e3a3bb | kernel.org | Patch |
| https://git.kernel.org/stable/c/b98e4e57e34d099a8f846fa54749654082975ea0 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-401 | Missing Release of Memory after Effective Lifetime | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 6.15, < 7.0.10 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 6, 2026 | Initial Analysis | [email protected] |
| Jun 26, 2026 | New CVE Received | kernel.org |