---
id: CVE-2026-89465
title: >-
  kernel: power: supply: rt9455: quiesce delayed work before teardown
  (CVE-2026-89465)
summary: >-
  A flaw was found in the Linux kernel, specifically within the rt9455 power
  supply driver. This vulnerability occurs due to improper management of delayed
  tasks when the device is being removed or if its initialization fails. A
  pending task…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe: CWE-825
vendor: Red Hat
product: Linux
affected:
  - >-
    Linux >= e86d69dd786e94046b8f5be7df1b9a8226a40b2a <
    442c60c08ec23ac45da0a58877cab05e0a58f4ea
  - >-
    Linux >= e86d69dd786e94046b8f5be7df1b9a8226a40b2a <
    df67c7a2fff8414aa766b8cd5ffe11ec1ca27d02
  - >-
    Linux >= e86d69dd786e94046b8f5be7df1b9a8226a40b2a <
    1b9978433c61a9b46e48832a1ebceee1cf5c9eb4
  - >-
    Linux >= e86d69dd786e94046b8f5be7df1b9a8226a40b2a <
    7323e562f6961e4b7bce3225cde4ecbc78260deb
  - >-
    Linux >= e86d69dd786e94046b8f5be7df1b9a8226a40b2a <
    3e7a1ebc32fad5a558254a478efd401c17a24381
  - Linux 4.2
published: '2026-09-11'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T20:02:29+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89465.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89465.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-89465'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2532410'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-89465'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89465'
  - url: >-
      https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89465.mbox
  - url: 'https://git.kernel.org/stable/c/442c60c08ec23ac45da0a58877cab05e0a58f4ea'
  - url: 'https://git.kernel.org/stable/c/df67c7a2fff8414aa766b8cd5ffe11ec1ca27d02'
  - url: 'https://git.kernel.org/stable/c/1b9978433c61a9b46e48832a1ebceee1cf5c9eb4'
  - url: 'https://git.kernel.org/stable/c/7323e562f6961e4b7bce3225cde4ecbc78260deb'
  - url: 'https://git.kernel.org/stable/c/3e7a1ebc32fad5a558254a478efd401c17a24381'
tags:
  - csaf
  - vex
  - red-hat
  - cve.org
  - score-dispute
epss: 0.00196
epssPercentile: 0.08204
scores:
  vendor: 5.5
  cna: 8.4
ingestedAt: '2026-09-14T15:23:07.453Z'
---

## Overview

A flaw was found in the Linux kernel, specifically within the rt9455 power supply driver. This vulnerability occurs due to improper management of delayed tasks when the device is being removed or if its initialization fails. A pending task can attempt to access memory that has already been released, leading to a use-after-free condition. This could allow a local attacker to cause the system to crash, resulting in a Denial of Service, or potentially lead to privilege escalation.

## Vendor advisories

- **Red Hat VEX** · Moderate · updated 2026-09-17 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89465.json)

**kernel: power: supply: rt9455: quiesce delayed work before teardown** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-17.

Not affected:

- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 6
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat OpenShift Container Platform 4

## Remediation

Refer to the advisory for fix availability.
