{"api_version":"1","generated_at":"2026-09-29T20:44:44+00:00","cve":"CVE-2026-89938","urls":{"html":"https://cve.report/CVE-2026-89938","api":"https://cve.report/api/cve/CVE-2026-89938.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-89938","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-89938"},"summary":{"title":"iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF","description":"In the Linux kernel, the following vulnerability has been resolved:\n\niio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF\n\nThe atlas driver requests its hardware data-ready IRQ with\ndevm_request_threaded_irq(); its threaded handler queues an irq_work,\natlas_work_handler(), that calls iio_trigger_poll(data->trig).\n\nThe IRQ is devm-managed, so free_irq() runs from the devres unwind after\natlas_remove() returns without flushing that irq_work.  Once a buffer is\nenabled, conversion-complete IRQs keep firing and queueing it; a pending\nirq_work can therefore run after the unwind has freed atlas_data/indio_dev\nand the trigger, when atlas_work_handler() derives the atlas_data pointer\nvia container_of() and dereferences data->trig, a use-after-free.\n\nCall iio_trigger_poll_nested() directly from the threaded handler instead\nof bouncing through irq_work.  free_irq() then drains the threaded handler,\nclosing the window; other iio drivers with a threaded data-ready IRQ do the\nsame (e.g. bmi270).\n\nThis issue was found by an in-house static analysis tool.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-16 11:17:03","updated_at":"2026-09-16 15:18:19"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/be61c8c6252671ecf1fee0ad90f87669e0be1e20","name":"https://git.kernel.org/stable/c/be61c8c6252671ecf1fee0ad90f87669e0be1e20","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/91e12b0fbd7047d02bf4ef4dbc491b9ef0159250","name":"https://git.kernel.org/stable/c/91e12b0fbd7047d02bf4ef4dbc491b9ef0159250","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/30b0d44c978bbc857bd68b71dab371805653de70","name":"https://git.kernel.org/stable/c/30b0d44c978bbc857bd68b71dab371805653de70","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/f64b437641b5a70c18bb0fd38da2b69d8926c871","name":"https://git.kernel.org/stable/c/f64b437641b5a70c18bb0fd38da2b69d8926c871","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/2071624c3d0f497ca91da78858e6f30d7112fea6","name":"https://git.kernel.org/stable/c/2071624c3d0f497ca91da78858e6f30d7112fea6","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89938","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89938","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 7103b99b031cb0ff6979331757bfc4893f37ae9e f64b437641b5a70c18bb0fd38da2b69d8926c871 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 7103b99b031cb0ff6979331757bfc4893f37ae9e 91e12b0fbd7047d02bf4ef4dbc491b9ef0159250 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 7103b99b031cb0ff6979331757bfc4893f37ae9e 2071624c3d0f497ca91da78858e6f30d7112fea6 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 7103b99b031cb0ff6979331757bfc4893f37ae9e 30b0d44c978bbc857bd68b71dab371805653de70 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 7103b99b031cb0ff6979331757bfc4893f37ae9e be61c8c6252671ecf1fee0ad90f87669e0be1e20 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4.8","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 4.8 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.157 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.110 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.51 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.5 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/iio/chemical/atlas-sensor.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"f64b437641b5a70c18bb0fd38da2b69d8926c871","status":"affected","version":"7103b99b031cb0ff6979331757bfc4893f37ae9e","versionType":"git"},{"lessThan":"91e12b0fbd7047d02bf4ef4dbc491b9ef0159250","status":"affected","version":"7103b99b031cb0ff6979331757bfc4893f37ae9e","versionType":"git"},{"lessThan":"2071624c3d0f497ca91da78858e6f30d7112fea6","status":"affected","version":"7103b99b031cb0ff6979331757bfc4893f37ae9e","versionType":"git"},{"lessThan":"30b0d44c978bbc857bd68b71dab371805653de70","status":"affected","version":"7103b99b031cb0ff6979331757bfc4893f37ae9e","versionType":"git"},{"lessThan":"be61c8c6252671ecf1fee0ad90f87669e0be1e20","status":"affected","version":"7103b99b031cb0ff6979331757bfc4893f37ae9e","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/iio/chemical/atlas-sensor.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"4.8"},{"lessThan":"4.8","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.157","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.110","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.51","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.5","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.157","versionStartIncluding":"4.8","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.110","versionStartIncluding":"4.8","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.51","versionStartIncluding":"4.8","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.5","versionStartIncluding":"4.8","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc1","versionStartIncluding":"4.8","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF\n\nThe atlas driver requests its hardware data-ready IRQ with\ndevm_request_threaded_irq(); its threaded handler queues an irq_work,\natlas_work_handler(), that calls iio_trigger_poll(data->trig).\n\nThe IRQ is devm-managed, so free_irq() runs from the devres unwind after\natlas_remove() returns without flushing that irq_work.  Once a buffer is\nenabled, conversion-complete IRQs keep firing and queueing it; a pending\nirq_work can therefore run after the unwind has freed atlas_data/indio_dev\nand the trigger, when atlas_work_handler() derives the atlas_data pointer\nvia container_of() and dereferences data->trig, a use-after-free.\n\nCall iio_trigger_poll_nested() directly from the threaded handler instead\nof bouncing through irq_work.  free_irq() then drains the threaded handler,\nclosing the window; other iio drivers with a threaded data-ready IRQ do the\nsame (e.g. bmi270).\n\nThis issue was found by an in-house static analysis tool."}],"metrics":[{"cvssV3_1":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:L - The use-after-free is reached from local IIO sysfs/chardev buffer enable on the Atlas I2C chemical sensor plus driver teardown (sysfs unbind, rmmod, or parent adapter removal). There is no network, Bluetooth, or remote-protocol path into atlas_interrupt_handler or atlas_work_handler.\nAC:L - With the IIO buffer enabled, conversion-complete IRQs keep queueing irq_work every 450-650ms. atlas_remove() never calls irq_work_sync(), so pending work runs after the synchronous devres unwind frees atlas_data. The attacker controls buffer enable and bind/unbind retries; on PREEMPT_RT or CPUs without an irq_work IPI the window is milliseconds.\nPR:L - IIO buffer/enable is mode 0644 with no capability check, and on industrial/IoT water-quality systems that ship Atlas OEM SM sensors those nodes are commonly group-accessible to monitoring services. Per driver-removal UAF scoring, an unprivileged local user can drive the IRQ/irq_work side while teardown proceeds; init-namespace root is not required.\nUI:N - The attacker enables the IIO buffer themselves and coordinates driver unbind or module teardown; no separate victim action such as plugging hardware or mounting a filesystem is required.\nS:U - The use-after-free corrupts kernel heap objects (atlas_data and the IIO trigger) in the host kernel's own security authority. This is a standard local kernel privilege-escalation path, not a VM, IOMMU, or sandbox boundary crossing.\nC:H - atlas_work_handler() recovers freed atlas_data via container_of() and dereferences data->trig. A use-after-free of that sprayable driver-private object yields an arbitrary kernel read primitive, including via iio_trigger_poll() walking attacker-controlled trigger state.\nI:H - After spraying the freed atlas_data, data->trig is attacker-controlled, so iio_trigger_poll() performs atomic updates and generic_handle_irq() on attacker-chosen IRQ numbers. That is an arbitrary kernel write and control-flow hijack primitive, consistent with use-after-free scoring.\nA:H - The pending irq_work running against freed atlas_data and the IIO trigger causes a kernel oops or panic (KASAN use-after-free or a wild dereference of data->trig), so availability impact is high even without a full exploit."}]}],"providerMetadata":{"dateUpdated":"2026-09-16T14:40:24.952Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/f64b437641b5a70c18bb0fd38da2b69d8926c871"},{"url":"https://git.kernel.org/stable/c/91e12b0fbd7047d02bf4ef4dbc491b9ef0159250"},{"url":"https://git.kernel.org/stable/c/2071624c3d0f497ca91da78858e6f30d7112fea6"},{"url":"https://git.kernel.org/stable/c/30b0d44c978bbc857bd68b71dab371805653de70"},{"url":"https://git.kernel.org/stable/c/be61c8c6252671ecf1fee0ad90f87669e0be1e20"}],"title":"iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-89938","datePublished":"2026-09-16T10:32:27.012Z","dateReserved":"2026-09-11T19:38:34.776Z","dateUpdated":"2026-09-16T14:40:24.952Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-16 11:17:03","lastModifiedDate":"2026-09-16 15:18:19","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"89938","Ordinal":"1","Title":"iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fi","CVE":"CVE-2026-89938","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"89938","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\niio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF\n\nThe atlas driver requests its hardware data-ready IRQ with\ndevm_request_threaded_irq(); its threaded handler queues an irq_work,\natlas_work_handler(), that calls iio_trigger_poll(data->trig).\n\nThe IRQ is devm-managed, so free_irq() runs from the devres unwind after\natlas_remove() returns without flushing that irq_work.  Once a buffer is\nenabled, conversion-complete IRQs keep firing and queueing it; a pending\nirq_work can therefore run after the unwind has freed atlas_data/indio_dev\nand the trigger, when atlas_work_handler() derives the atlas_data pointer\nvia container_of() and dereferences data->trig, a use-after-free.\n\nCall iio_trigger_poll_nested() directly from the threaded handler instead\nof bouncing through irq_work.  free_irq() then drains the threaded handler,\nclosing the window; other iio drivers with a threaded data-ready IRQ do the\nsame (e.g. bmi270).\n\nThis issue was found by an in-house static analysis tool.","Type":"Description","Title":"iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fi"}]}}}