CVE-2026-89467

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/09/2026
Last modified:
03/10/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> power: supply: qcom_battmgr: fix use-after-free<br /> <br /> qcom_battmgr_pdr_notify() queues enable_work when the PMIC GLINK service<br /> comes up, and the worker recovers battmgr through container_of() to issue<br /> firmware requests. The PMIC GLINK client stays on the client list until<br /> its devres release action runs, so a PDR notification can keep queueing<br /> the work, and a pending or running worker can access battmgr after devres<br /> frees it.<br /> <br /> Make enable_work device-managed with devm_work_autocancel(), registered<br /> before the PMIC GLINK client is allocated. The devres cleanup then<br /> releases the client first, so no further notification can queue the work,<br /> and cancels the work before battmgr is freed.<br /> <br /> This issue was found by an in-house static analysis tool.

Impact