From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4BA1851C321 for ; Fri, 11 Sep 2026 19:51:27 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156307; cv=none; b=eE4GA/Mrg4XotXXFc8UkFk8fQAU9Gp7HV02mD7O2gvG607cXHFLVEFanTyXlmD6ueIEL55DXePCme5+7OZ52Dkv0fl+wHgPlDgt8G987CAbI8EXpSIPsYXEkJg2+5f9Q4ioEg6iAZ/ZSvpoT5ktzGlBpJhbdfh6jfa4IuqQAQeg= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156307; c=relaxed/simple; bh=O6P9FdlrzXx3Z7dgnoNu3AE9iPBMHXSztAaq4VdMRS4=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=g11hwxKbfYmPVDEO1McMcSpF0fJqlvuqXu4JiFlX/ZHTWytiFVQMtmAGNhcj6+D57FbTOXzq2Cp3fLvGgGYQpAzz/hzgqe3MrytBlBUMbepqhZKW8EqyHNndJDXQRVmM3WSl5VwmdcyLGIQMke/imdPXfvDJRr0gJ/DF238PJC8= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=CwYlT6wO; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="CwYlT6wO" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 70D201F000FF; Fri, 11 Sep 2026 19:51:26 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789156287; bh=ov9f8AVWaG2aD5T4h+LJFWr6HNq2rDYL9TTZiWTaBtc=; h=From:To:Cc:Subject:Date:Reply-To; b=CwYlT6wO4tp8rmVusA1lTkeipPR/hfFAG907jTOCXGYMXeuRBWPW/DTgNLZPtfdaa iQCPDEDLn1FRHY98ls3n3NZ3ZDDWyHnZQZviFXlxCN8hEcAdxJCaBlvWLxhognInyZ 5hm8YdVY87s9VCtTNz9HGvKjTfjCK2zwJNnqe7Xc= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-89466: power: supply: qcom_battmgr: terminate the strings from firmware Date: Fri, 11 Sep 2026 21:42:35 +0200 Message-ID: <2026091102-CVE-2026-89466-8491@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=2859; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=k3UB0pFR1qdnx+pk8lVgacjHpCMZJ2LU+hqMZnO3lEU=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLIv3iZCPWbJq59fOjNUXMx5N4dfwaZxh+72PK3iI6Z /+Crw3dHbEsDIJMDLJiiixftvEc3V9xSNHL0PY0zBxWJpAhDFycAjCR+ycY5pdKh5msF+GJSK1+ d2iTXq11XdT8CIYF+4peGK19ZbXMzHUZ9+Xs0nuf7v/7BQA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: power: supply: qcom_battmgr: terminate the strings from firmware The qcom_battmgr_sc8280xp_strcpy() takes a Pascal-style string when the firmware sends one. Otherwise it copies all BATTMGR_STRING_LEN bytes and leaves the destination without a terminator. Those destinations are model_number, serial_number and oem_info, each BATTMGR_STRING_LEN and declared next to each other. They go out to user space as val->strval, which power_supply_format_property() prints with "%s", so a firmware string that fills the whole field makes that read run into the following members. Use strscpy() so the copy always terminates, the way the SM8350 path already does for the same field. The Linux kernel CVE team has assigned CVE-2026-89466 to this issue. Affected and fixed versions =========================== Issue introduced in 6.3 with commit 29e8142b5623b5949587bcc4f591c4e6595c4aca and fixed in 6.12.109 with commit 0e70a9b0d16acf7adebc4f386178a95da27c0027 Issue introduced in 6.3 with commit 29e8142b5623b5949587bcc4f591c4e6595c4aca and fixed in 6.18.50 with commit ee053561e21ce1e1741dd64ca5ddcdb92e40edc1 Issue introduced in 6.3 with commit 29e8142b5623b5949587bcc4f591c4e6595c4aca and fixed in 7.2.4 with commit 6cc6c28c9ab6e8ecf901397717a5b391b828cdaf Issue introduced in 6.3 with commit 29e8142b5623b5949587bcc4f591c4e6595c4aca and fixed in 7.3-rc1 with commit ab1112df8f4ffa88cb024dd370c432ced80f77d8 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-89466 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/power/supply/qcom_battmgr.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/0e70a9b0d16acf7adebc4f386178a95da27c0027 https://git.kernel.org/stable/c/ee053561e21ce1e1741dd64ca5ddcdb92e40edc1 https://git.kernel.org/stable/c/6cc6c28c9ab6e8ecf901397717a5b391b828cdaf https://git.kernel.org/stable/c/ab1112df8f4ffa88cb024dd370c432ced80f77d8