CVE-2026-89585

Source
https://cve.org/CVERecord?id=CVE-2026-89585
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-89585.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-89585
Downstream
Related
Published
2026-09-11T19:44:50Z
Modified
2026-09-25T18:26:59Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
auxdisplay: charlcd: cancel backlight work on registration failure
Details

In the Linux kernel, the following vulnerability has been resolved:

auxdisplay: charlcd: cancel backlight work on registration failure

With CONFIG_CHARLCD_BL_FLASH, charlcd_init() schedules bl_work before charlcd_register() calls misc_register(). If registration fails, the caller frees the charlcd object while delayed work still contains its address.

Add charlcd_deinit() to cancel the delayed work and turn the backlight off. Use it for both registration rollback and normal unregistration.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89585.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
39f8ea46724efbed3ca021863a22337c31be264c
Fixed
cd97b3c68fe3c06c8067cc59d7dff976c5b7ea04
Fixed
22586432c1aba89d9bd33f3173408dac830f220b
Fixed
6eaed64a32e550daf0dc9549742b3ab9e41d984f
Fixed
fe7ba73dde94c5f413b1588cd444b49105015dda
Fixed
84858671842ae5857b9ed1202b62f9045373dcd1
Fixed
ff2fb3c1e60cb247ea3e28c0ea0bea81c18f7755
Fixed
e3e3bf40916c1e810df03958cfa7ba6883cdce79

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-89585.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.12.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.109
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.50
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.4

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-89585.json"