Description
In the Linux kernel, the following vulnerability has been resolved:

power: supply: qcom_battmgr: terminate the strings from firmware

The qcom_battmgr_sc8280xp_strcpy() takes a Pascal-style string when the
firmware sends one. Otherwise it copies all BATTMGR_STRING_LEN bytes and
leaves the destination without a terminator.

Those destinations are model_number, serial_number and oem_info, each
BATTMGR_STRING_LEN and declared next to each other. They go out to user
space as val->strval, which power_supply_format_property() prints with
"%s", so a firmware string that fills the whole field makes that read run
into the following members.

Use strscpy() so the copy always terminates, the way the SM8350 path
already does for the same field.
Published: 2026-09-11
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Null termination failure causing read of adjacent memory
Action: Apply Patch
AI Analysis

Impact

The vulnerability occurs in the Linux kernel's Qualcomm battery manager driver when firmware supplies a string not properly terminated. The function qcom_battmgr_sc8280xp_strcpy copies a fixed length incoming string is shorter than the buffer. The destination buffers model_number, serial_number, and oem_info are contiguous; when a firmware string consumes the entire field, subsequent reads of the user space string output with "%s" expand into adjacent memory, potentially revealing sensitive data. The weakness corresponds to an out‑of‑bounds read (CWE‑125).

Affected Systems

The flaw affects any Linux system the kernel. The specific product is the Linux kernel; affected releases are unspecified, but the change is part of the kernel source referenced in the advisory.

Risk and Exploitability

The CVSS score is 3.3, indicating a low‑severity impact. The EPSS score is 0.00168 (<1%) and the vulnerability is not listed in CISA's KEV catalog, suggesting limited exploitation evidence to date. The likely attack vector involves firmware input, which would require access to firmware updates or an attacker who can tamper with the device's firmware. While the bug could lead to information disclosure, no remote code execution or denial of service is implied by the description.

Generated by OpenCVE AI on September 13, 2026 at 03:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that applies the strscpy change in qcom_battmgr_sc8280xp_strcpy, ensuring all firmware strings are properly null‑terminated.
  • Verify that firmware provides strings shorter than BATTMGR_STRING_LEN or that the firmware is compatible with the patched driver.
  • Restart the device after applying the kernel update to load the corrected driver.
  • If immediate kernel upgrade is not possible, limit the length of firmware strings to less than BATTMGR_STRING_LEN to avoid overrunning the destination buffer.

Generated by OpenCVE AI on September 13, 2026 at 03:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
References
Metrics threat_severity

None

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

threat_severity

Low


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: power: supply: qcom_battmgr: terminate the strings from firmware The qcom_battmgr_sc8280xp_strcpy() takes a Pascal-style string when the firmware sends one. Otherwise it copies all BATTMGR_STRING_LEN bytes and leaves the destination without a terminator. Those destinations are model_number, serial_number and oem_info, each BATTMGR_STRING_LEN and declared next to each other. They go out to user space as val->strval, which power_supply_format_property() prints with "%s", so a firmware string that fills the whole field makes that read run into the following members. Use strscpy() so the copy always terminates, the way the SM8350 path already does for the same field.
Title power: supply: qcom_battmgr: terminate the strings from firmware
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:29:36.261Z

Reserved: 2026-09-11T19:38:34.709Z

Link: CVE-2026-89466

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:27.673

Modified: 2026-09-13T07:17:10.013

Link: CVE-2026-89466

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-11T19:43:26Z

Links: CVE-2026-89466 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T05:15:04Z

Weaknesses