๐Ÿ” CVE Alert

CVE-2026-89737

UNKNOWN 0.0

usb: typec: thunderbolt: Disable work before freeing tbt on remove

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: usb: typec: thunderbolt: Disable work before freeing tbt on remove tbt_altmode_remove() drops the plug and cable references without draining tbt->work. The work function dereferences those references, and can also requeue itself in its error path. The VDM callbacks can queue the same work item. Disable and drain tbt->work before dropping the references. This waits for an existing invocation and prevents subsequent schedule_work() calls from queueing it during teardown. This issue was found by an in-house static analysis tool and confirmed by manual code review.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
100e257386595b3f1865ca8a991e2ba74f9701ff < ebb840d982a612261cfc8a7687735a140c6c7024 100e257386595b3f1865ca8a991e2ba74f9701ff < 0a25484fe22f621e151367a59a82330a22ac80bc 100e257386595b3f1865ca8a991e2ba74f9701ff < 92090f6ff2acc81e9dd99881dcfb4f8c1bdaabd3
Linux / Linux
6.14

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/ebb840d982a612261cfc8a7687735a140c6c7024 git.kernel.org: https://git.kernel.org/stable/c/0a25484fe22f621e151367a59a82330a22ac80bc git.kernel.org: https://git.kernel.org/stable/c/92090f6ff2acc81e9dd99881dcfb4f8c1bdaabd3