๐Ÿ” CVE Alert

CVE-2026-89938

UNKNOWN 0.0

iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF The atlas driver requests its hardware data-ready IRQ with devm_request_threaded_irq(); its threaded handler queues an irq_work, atlas_work_handler(), that calls iio_trigger_poll(data->trig). The IRQ is devm-managed, so free_irq() runs from the devres unwind after atlas_remove() returns without flushing that irq_work. Once a buffer is enabled, conversion-complete IRQs keep firing and queueing it; a pending irq_work can therefore run after the unwind has freed atlas_data/indio_dev and the trigger, when atlas_work_handler() derives the atlas_data pointer via container_of() and dereferences data->trig, a use-after-free. Call iio_trigger_poll_nested() directly from the threaded handler instead of bouncing through irq_work. free_irq() then drains the threaded handler, closing the window; other iio drivers with a threaded data-ready IRQ do the same (e.g. bmi270). This issue was found by an in-house static analysis tool.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
7103b99b031cb0ff6979331757bfc4893f37ae9e < f64b437641b5a70c18bb0fd38da2b69d8926c871 7103b99b031cb0ff6979331757bfc4893f37ae9e < 91e12b0fbd7047d02bf4ef4dbc491b9ef0159250 7103b99b031cb0ff6979331757bfc4893f37ae9e < 2071624c3d0f497ca91da78858e6f30d7112fea6 7103b99b031cb0ff6979331757bfc4893f37ae9e < 30b0d44c978bbc857bd68b71dab371805653de70 7103b99b031cb0ff6979331757bfc4893f37ae9e < be61c8c6252671ecf1fee0ad90f87669e0be1e20
Linux / Linux
4.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/f64b437641b5a70c18bb0fd38da2b69d8926c871 git.kernel.org: https://git.kernel.org/stable/c/91e12b0fbd7047d02bf4ef4dbc491b9ef0159250 git.kernel.org: https://git.kernel.org/stable/c/2071624c3d0f497ca91da78858e6f30d7112fea6 git.kernel.org: https://git.kernel.org/stable/c/30b0d44c978bbc857bd68b71dab371805653de70 git.kernel.org: https://git.kernel.org/stable/c/be61c8c6252671ecf1fee0ad90f87669e0be1e20