← All Advisories

CVE-2026-89467

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-89467

Key Details

CVECVE-2026-89467
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

power: supply: qcom_battmgr: fix use-after-free

qcom_battmgr_pdr_notify() queues enable_work when the PMIC GLINK service

comes up, and the worker recovers battmgr through container_of() to issue

firmware requests. The PMIC GLINK client stays on the client list until

its devres release action runs, so a PDR notification can keep queueing

the work, and a pending or running worker can access battmgr after devres

frees it.

Make enable_work device-managed with devm_work_autocancel(), registered

before the PMIC GLINK client is allocated. The devres cleanup then

releases the client first, so no further notification can queue the work,

and cancels the work before battmgr is freed.

This issue was found by an in-house static analysis tool. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-89467
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-89467