From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E27AF572696 for ; Fri, 11 Sep 2026 19:51:30 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156303; cv=none; b=VnjXEXezxlikMnJTWfsFU3muCEr6xkm0seQtVh2Zv9hCrpHNQOkFi4jSEBTJRO7Y0/+f0IF1WeTZGdq60CkdWE39MEdvB/wYCeR1qTRNDAJYIEP71H/gG9L91wMSoZeQ3/tUdhfpo6gVu0bfP3euVNSur4xTbdQ/EvpQBi/QQbk= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156303; c=relaxed/simple; bh=+PGXcbJp+Zgt60/0g1OqPuAYHB/nQL9XQT8VieWNESQ=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=M71tGueQz5LL/9d66H8eo74A9qcmcZrjZ3QDZ8NLJOjdDXbKyfykU985z/dzpFyAwVwfMqHIz8zku2/XqTtHMnoYoUKZSlj5SUZmWnXzS5UIBcMVQikLWf8cWFjcMPr85hPDzOWcvAheRdbzPEfjYHuUwdhwATJ+d/Ym/2Um+50= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=DJoaKD0V; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="DJoaKD0V" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 5A8C51F00898; Fri, 11 Sep 2026 19:51:29 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789156289; bh=Zcog5CHOuoJF6tb9I0Z5Ph4UxbTEnlB70tSbudGhhlg=; h=From:To:Cc:Subject:Date:Reply-To; b=DJoaKD0VP2hXaty8hDIgK1QFWxrkIO9bDStXYwZ+vh/6CBzfUsIrFp+O4c1oVM5j9 vDN4du2kHvoqy8EJrXhNI1B9XsCySrQdEwzXylkMvYZE2D09LIfweciU8xaki9pcdy rv6DOlHG62xj7LKU64QtJQbUi17b0ydhq/JsrroU= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-89467: power: supply: qcom_battmgr: fix use-after-free Date: Fri, 11 Sep 2026 21:42:36 +0200 Message-ID: <2026091102-CVE-2026-89467-6f38@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=2699; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=SxuvuiZxhmSjEzGFtq+2mkVj8tcqbkPyqBH1K1MvbUE=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLIv3yBfZPZb3MenZH9cE5NyV7Vga02i/ev6pj07SFI gKdG4qfdcSyMAgyMciKKbJ82cZzdH/FIUUvQ9vTMHNYmUCGMHBxCsBEzM8zzGZ1K6q4/nuN3+2f 2zNnMK9rrjeVEmCYK977fu48E79t//fpXVvmm9/if7uHGwA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: power: supply: qcom_battmgr: fix use-after-free qcom_battmgr_pdr_notify() queues enable_work when the PMIC GLINK service comes up, and the worker recovers battmgr through container_of() to issue firmware requests. The PMIC GLINK client stays on the client list until its devres release action runs, so a PDR notification can keep queueing the work, and a pending or running worker can access battmgr after devres frees it. Make enable_work device-managed with devm_work_autocancel(), registered before the PMIC GLINK client is allocated. The devres cleanup then releases the client first, so no further notification can queue the work, and cancels the work before battmgr is freed. This issue was found by an in-house static analysis tool. The Linux kernel CVE team has assigned CVE-2026-89467 to this issue. Affected and fixed versions =========================== Issue introduced in 6.3 with commit 29e8142b5623b5949587bcc4f591c4e6595c4aca and fixed in 6.18.50 with commit 06618447029c6dddaa02f6e9528efe5dd49fc329 Issue introduced in 6.3 with commit 29e8142b5623b5949587bcc4f591c4e6595c4aca and fixed in 7.2.4 with commit 49fbcd3da2958159370d25dafbf736e654a4d59b Issue introduced in 6.3 with commit 29e8142b5623b5949587bcc4f591c4e6595c4aca and fixed in 7.3-rc1 with commit 4e40befedfc8ed86f44e1f81df92d13c149c9f8d Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-89467 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/power/supply/qcom_battmgr.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/06618447029c6dddaa02f6e9528efe5dd49fc329 https://git.kernel.org/stable/c/49fbcd3da2958159370d25dafbf736e654a4d59b https://git.kernel.org/stable/c/4e40befedfc8ed86f44e1f81df92d13c149c9f8d