{"id":"CVE-2026-89585","title":"kernel: auxdisplay: charlcd: cancel backlight work on registration failure (CVE-2026-89585)","summary":"A flaw was found in the `auxdisplay: charlcd` component of the Linux kernel. This use-after-free vulnerability occurs when the `charlcd_register()` function fails, leading to the `charlcd` object being freed while a delayed work item still…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-825","vendor":"Red Hat","product":"Linux","affected":["Linux >= 39f8ea46724efbed3ca021863a22337c31be264c < cd97b3c68fe3c06c8067cc59d7dff976c5b7ea04","Linux >= 39f8ea46724efbed3ca021863a22337c31be264c < 22586432c1aba89d9bd33f3173408dac830f220b","Linux >= 39f8ea46724efbed3ca021863a22337c31be264c < 6eaed64a32e550daf0dc9549742b3ab9e41d984f","Linux >= 39f8ea46724efbed3ca021863a22337c31be264c < fe7ba73dde94c5f413b1588cd444b49105015dda","Linux >= 39f8ea46724efbed3ca021863a22337c31be264c < 84858671842ae5857b9ed1202b62f9045373dcd1","Linux >= 39f8ea46724efbed3ca021863a22337c31be264c < ff2fb3c1e60cb247ea3e28c0ea0bea81c18f7755","Linux >= 39f8ea46724efbed3ca021863a22337c31be264c < e3e3bf40916c1e810df03958cfa7ba6883cdce79","Linux 4.12"],"published":"2026-09-11","updated":"2026-09-18","sourceUpdated":"2026-09-18T22:12:28+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89585.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89585.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89585"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532284"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89585"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89585"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89585.mbox"},{"url":"https://git.kernel.org/stable/c/cd97b3c68fe3c06c8067cc59d7dff976c5b7ea04"},{"url":"https://git.kernel.org/stable/c/22586432c1aba89d9bd33f3173408dac830f220b"},{"url":"https://git.kernel.org/stable/c/6eaed64a32e550daf0dc9549742b3ab9e41d984f"},{"url":"https://git.kernel.org/stable/c/fe7ba73dde94c5f413b1588cd444b49105015dda"},{"url":"https://git.kernel.org/stable/c/84858671842ae5857b9ed1202b62f9045373dcd1"},{"url":"https://git.kernel.org/stable/c/ff2fb3c1e60cb247ea3e28c0ea0bea81c18f7755"},{"url":"https://git.kernel.org/stable/c/e3e3bf40916c1e810df03958cfa7ba6883cdce79"}],"tags":["csaf","vex","red-hat","cve.org","score-dispute"],"epss":0.00164,"epssPercentile":0.06026,"scores":{"vendor":5.5,"cna":7.8},"ingestedAt":"2026-09-14T15:23:07.451Z","slug":"CVE-2026-89585","body":"## Overview\n\nA flaw was found in the `auxdisplay: charlcd` component of the Linux kernel. This use-after-free vulnerability occurs when the `charlcd_register()` function fails, leading to the `charlcd` object being freed while a delayed work item still retains its address. A local attacker could potentially exploit this to cause a system crash or other undefined behavior.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89585.json)\n\n**kernel: auxdisplay: charlcd: cancel backlight work on registration failure** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-18.\n\nNot affected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nRefer to the advisory for fix availability.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":208088,"id":"CVE-2026-89585","ts":1789922707175,"field":"cvss","old":"7.8","new":"5.5"},{"seq":208087,"id":"CVE-2026-89585","ts":1789922707175,"field":"severity","old":"high","new":"medium"},{"seq":197892,"id":"CVE-2026-89585","ts":1789384320837,"field":"cvss","old":"4.4","new":"7.8"},{"seq":197891,"id":"CVE-2026-89585","ts":1789384320837,"field":"severity","old":"medium","new":"high"},{"seq":183467,"id":"CVE-2026-89585","ts":1789356675485,"field":"cvss","old":"7.8","new":"4.4"},{"seq":183466,"id":"CVE-2026-89585","ts":1789356675485,"field":"severity","old":"high","new":"medium"},{"seq":153402,"id":"CVE-2026-89585","ts":1789285350369,"field":"cvss","old":null,"new":"7.8"},{"seq":153401,"id":"CVE-2026-89585","ts":1789285350369,"field":"severity","old":"none","new":"high"},{"seq":147438,"id":"CVE-2026-89585","ts":1789270210910,"field":"cvss","old":null,"new":"4.4"},{"seq":147437,"id":"CVE-2026-89585","ts":1789270210910,"field":"severity","old":"none","new":"medium"},{"seq":109192,"id":"CVE-2026-89585","ts":1789183730670,"field":"cvss","old":null,"new":"4.4"},{"seq":109191,"id":"CVE-2026-89585","ts":1789183730670,"field":"severity","old":"none","new":"medium"}]}