CVE-2026-89466
Received Received - Intake

Buffer Overflow in Qualcomm Power Supply Driver

Vulnerability report for CVE-2026-89466, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: power: supply: qcom_battmgr: terminate the strings from firmware The qcom_battmgr_sc8280xp_strcpy() takes a Pascal-style string when the firmware sends one. Otherwise it copies all BATTMGR_STRING_LEN bytes and leaves the destination without a terminator. Those destinations are model_number, serial_number and oem_info, each BATTMGR_STRING_LEN and declared next to each other. They go out to user space as val->strval, which power_supply_format_property() prints with "%s", so a firmware string that fills the whole field makes that read run into the following members. Use strscpy() so the copy always terminates, the way the SM8350 path already does for the same field.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
qualcomm qcom_battmgr *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Linux kernel's power supply subsystem, specifically in the Qualcomm battery manager driver (qcom_battmgr). It involves improper handling of strings from firmware, where Pascal-style strings are not properly terminated. This can lead to buffer overflows when firmware sends strings that fill the entire allocated space, causing subsequent memory to be read incorrectly.

Detection Guidance

This vulnerability is specific to the Linux kernel's power supply subsystem for Qualcomm battery management. Detection requires checking kernel logs for related errors or inspecting the qcom_battmgr driver for improper string handling. No direct network detection commands are applicable.

Impact Analysis

An attacker with control over firmware could exploit this to cause memory corruption, potentially leading to system crashes, privilege escalation, or unauthorized data access. Systems using affected Qualcomm battery manager hardware may be vulnerable.

Compliance Impact

This vulnerability could potentially lead to information disclosure if firmware strings are not properly terminated, causing unintended data exposure in fields like model_number, serial_number, or oem_info. Such exposure may violate data protection principles under GDPR or HIPAA if sensitive device identifiers are leaked.

Mitigation Strategies

Update your Linux kernel to a patched version that includes the fix for CVE-2026-89466. The vulnerability is resolved by using strscpy() instead of unsafe string copying in the qcom_battmgr driver.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89466. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart