CVE-2026-89467
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
11/09/2026
Última modificación:
03/10/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
power: supply: qcom_battmgr: fix use-after-free<br />
<br />
qcom_battmgr_pdr_notify() queues enable_work when the PMIC GLINK service<br />
comes up, and the worker recovers battmgr through container_of() to issue<br />
firmware requests. The PMIC GLINK client stays on the client list until<br />
its devres release action runs, so a PDR notification can keep queueing<br />
the work, and a pending or running worker can access battmgr after devres<br />
frees it.<br />
<br />
Make enable_work device-managed with devm_work_autocancel(), registered<br />
before the PMIC GLINK client is allocated. The devres cleanup then<br />
releases the client first, so no further notification can queue the work,<br />
and cancels the work before battmgr is freed.<br />
<br />
This issue was found by an in-house static analysis tool.


