Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-89467

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
11/09/2026
Última modificación:
03/10/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> power: supply: qcom_battmgr: fix use-after-free<br /> <br /> qcom_battmgr_pdr_notify() queues enable_work when the PMIC GLINK service<br /> comes up, and the worker recovers battmgr through container_of() to issue<br /> firmware requests. The PMIC GLINK client stays on the client list until<br /> its devres release action runs, so a PDR notification can keep queueing<br /> the work, and a pending or running worker can access battmgr after devres<br /> frees it.<br /> <br /> Make enable_work device-managed with devm_work_autocancel(), registered<br /> before the PMIC GLINK client is allocated. The devres cleanup then<br /> releases the client first, so no further notification can queue the work,<br /> and cancels the work before battmgr is freed.<br /> <br /> This issue was found by an in-house static analysis tool.

Impacto