All of lore.kernel.org
 help / color / mirror / Atom feed
* CVE-2026-89473: power: supply: bq25890: Fix power_supply reference leak
@ 2026-09-11 19:42 Greg Kroah-Hartman
  0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-09-11 19:42 UTC (permalink / raw)
  To: linux-cve-announce; +Cc: Greg Kroah-Hartman

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

power: supply: bq25890: Fix power_supply reference leak

bq25890_fw_probe() acquires a reference to a secondary charger using
power_supply_get_by_name(), but the reference is not released on later
probe failures or on driver detach.

In particular, failures after bq25890_fw_probe() returns successfully,
such as a failure in bq25890_hw_init(), also leak the reference.

Register a device-managed cleanup action immediately after acquiring
the secondary charger. This releases the reference on all subsequent
probe failures and on driver detach.

Found by code review.

The Linux kernel CVE team has assigned CVE-2026-89473 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 6.3 with commit d54bf877fd878ee45cbc88d399fb98b0b1c4484d and fixed in 6.12.109 with commit 81b558afda9321c1a70971a39071d156f3e26950
	Issue introduced in 6.3 with commit d54bf877fd878ee45cbc88d399fb98b0b1c4484d and fixed in 6.18.50 with commit 238320ad029a3eedabb86286a28cab55bca629b9
	Issue introduced in 6.3 with commit d54bf877fd878ee45cbc88d399fb98b0b1c4484d and fixed in 7.2.4 with commit 58f1025eca92734eadc063715b98f62538286468
	Issue introduced in 6.3 with commit d54bf877fd878ee45cbc88d399fb98b0b1c4484d and fixed in 7.3-rc1 with commit 863c32a83e4235eb0cbf6106f2b124e645302156

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-89473
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	drivers/power/supply/bq25890_charger.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/81b558afda9321c1a70971a39071d156f3e26950
	https://git.kernel.org/stable/c/238320ad029a3eedabb86286a28cab55bca629b9
	https://git.kernel.org/stable/c/58f1025eca92734eadc063715b98f62538286468
	https://git.kernel.org/stable/c/863c32a83e4235eb0cbf6106f2b124e645302156

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-09-11 19:51 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-11 19:42 CVE-2026-89473: power: supply: bq25890: Fix power_supply reference leak Greg Kroah-Hartman

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.