CVE-2026-90394
Published Sep 17, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: power: supply: sc2731_charger: cancel work on remove The USB notifier and initial charger detection can schedule info->work. The remove path unregisters the notifier, but does not cancel queued or running work before the devm-allocated driver data is released. Set the platform drvdata used by remove, then cancel the work after unregistering the notifier. This issue was found by a static analysis tool.
Is your site exposed to CVE-2026-90394?
Run a free security scan — no signup, results in seconds.
References
Other References
https://git.kernel.org/stable/c/05c188addc6d1af51e28496e95096f4df9a000e9
https://git.kernel.org/stable/c/232e9e946b496e4706e2f34ce4a617460d8ae713
https://git.kernel.org/stable/c/972d88069050d0272b776145b824198b8f899dce
https://git.kernel.org/stable/c/aab9d81a415c6653b44b057695ebfbba34dc9556
https://git.kernel.org/stable/c/bb74a5ab30963022981381ea6aee176fd0c7957c
https://git.kernel.org/stable/c/c6df6e0c099086bc553d44410015cc81795070e6
https://git.kernel.org/stable/c/d5266b4c5c77152e386a3a2d9d5244b3b6cbd57a
https://git.kernel.org/stable/c/dfc859bb8d332c525872f1a44028137724fa1998
Frequently Asked Questions
What is CVE-2026-90394? +
In the Linux kernel, the following vulnerability has been resolved:
power: supply: sc2731_charger: cancel work on remove
The USB notifier and initial charger detection can schedule info->work.
The remove path unregisters the notifier, but does not cancel queued or
running work before the devm-allocated driver data is released.
Set the platform drvdata used by remove, then cancel the work after
unregistering the notifier.
This issue was found by a static analysis tool.
How do I check if I'm vulnerable to CVE-2026-90394? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.