CVE-2026-89473
Received Received - Intake

Power Supply Reference Leak in bq25890 Kernel Driver

Vulnerability report for CVE-2026-89473, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: power: supply: bq25890: Fix power_supply reference leak bq25890_fw_probe() acquires a reference to a secondary charger using power_supply_get_by_name(), but the reference is not released on later probe failures or on driver detach. In particular, failures after bq25890_fw_probe() returns successfully, such as a failure in bq25890_hw_init(), also leak the reference. Register a device-managed cleanup action immediately after acquiring the secondary charger. This releases the reference on all subsequent probe failures and on driver detach. Found by code review.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a power supply reference leak in the Linux kernel's bq25890 driver. The issue occurs when the driver acquires a reference to a secondary charger using power_supply_get_by_name() but fails to release it during probe failures or driver detachment. This leads to a memory leak where the reference remains allocated.

Detection Guidance

This vulnerability is specific to the Linux kernel's bq25890 power supply driver and involves a reference leak in the power_supply subsystem. Detection requires checking for kernel logs or driver issues related to the bq25890 module. Use commands like 'dmesg | grep bq25890' or 'journalctl -k | grep bq25890' to identify probe failures or reference leaks.

Impact Analysis

The impact is primarily on system stability and resource usage. A leaked reference can cause gradual memory exhaustion, leading to degraded performance or crashes over time. It may also affect the functionality of power management systems relying on the bq25890 driver.

Compliance Impact

This vulnerability does not directly affect compliance with standards like GDPR or HIPAA as it involves a power supply reference leak in the Linux kernel, which is unrelated to data protection or privacy requirements.

Mitigation Strategies

Apply the latest kernel update that includes the fix for CVE-2026-89473. If updating is not immediately possible, monitor the affected systems for power supply driver issues and avoid unloading/reloading the bq25890 module until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89473. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart