Description
In the Linux kernel, the following vulnerability has been resolved:

power: supply: qcom_battmgr: terminate the strings from firmware

The qcom_battmgr_sc8280xp_strcpy() takes a Pascal-style string when the
firmware sends one. Otherwise it copies all BATTMGR_STRING_LEN bytes and
leaves the destination without a terminator.

Those destinations are model_number, serial_number and oem_info, each
BATTMGR_STRING_LEN and declared next to each other. They go out to user
space as val->strval, which power_supply_format_property() prints with
"%s", so a firmware string that fills the whole field makes that read run
into the following members.

Use strscpy() so the copy always terminates, the way the SM8350 path
already does for the same field.
Published: 2026-09-11
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Out‑of‑bounds read causing information disclosure
Action: Patch Kernel
AI Analysis

Impact

An out‑of‑bounds read occurs in the Linux kernel’s Qualcomm battery manager driver when firmware supplies a string that is not properly null‑terminated. The driver copies the string into three adjacent buffers – model_number, serial_number and oem_info – each sized BATTMGR_STRING_LEN. If a firmware string consumes the entire buffer, the subsequent string prints with printf "%s" continue into the following memory, exposing data beyond the intended fields. This defect corresponds to CWE‑125 does not provide direct code execution or denial of service.

Affected Systems

The flaw resides in the Linux kernel’s qcom_battmgr driver; any kernel package that contains this module before the patch is affected. Systems operating Qualcomm hardware such as the SC8280XP that depend on the battery manager firmware are at risk. Exact kernel release versions are not documented, but any build prior to the commit that introduced strscpy handling will be vulnerable.

Risk and Exploitability

The CVSS v3.1 score of 7.7 indicates a medium‑to‑high impact. Attackers would need to supply malformed firmware or gain the ability to alter firmware strings, which typically requires privileged access; the likely attack vector is through manipulation of the battery manager firmware, inferred from the need to control firmware strings during device operation. The EPSS score of < 1% indicates a very low exploitation probability. No remote code execution or denial‑of‑service effect is described, so the primary risk is potential information disclosure.

Generated by OpenCVE AI on September 21, 2026 at 01:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that incorporates the strscpy change to qcom_battmgr_sc8280xp_strcpy, ensuring firmware strings are properly null‑terminated.
  • Verify that device firmware complies with the string length limits or update the firmware to a version compatible with the patched driver.
  • If a kernel upgrade cannot be performed immediately, constrain firmware strings to less than BATTMGR_STRING_LEN before they are parsed by the driver.

Generated by OpenCVE AI on September 21, 2026 at 01:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
References
Metrics threat_severity

None

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

threat_severity

Low


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: power: supply: qcom_battmgr: terminate the strings from firmware The qcom_battmgr_sc8280xp_strcpy() takes a Pascal-style string when the firmware sends one. Otherwise it copies all BATTMGR_STRING_LEN bytes and leaves the destination without a terminator. Those destinations are model_number, serial_number and oem_info, each BATTMGR_STRING_LEN and declared next to each other. They go out to user space as val->strval, which power_supply_format_property() prints with "%s", so a firmware string that fills the whole field makes that read run into the following members. Use strscpy() so the copy always terminates, the way the SM8350 path already does for the same field.
Title power: supply: qcom_battmgr: terminate the strings from firmware
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:00:05.333Z

Reserved: 2026-09-11T19:38:34.709Z

Link: CVE-2026-89466

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:27.673

Modified: 2026-09-14T13:19:03.020

Link: CVE-2026-89466

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-11T19:43:26Z

Links: CVE-2026-89466 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T01:15:03Z

Weaknesses