Impact
A use-after-free flaw was identified in the qcom_battmgr power supply driver of the Linux kernel. When the PMIC GLINK service rises a notification, the driver queues a work item that later dereferences a battmgr structure that has already been freed by the device-resource cleanup. This race can corrupt kernel memory and cause a kernel panic, resulting in a local denial of service.
Affected Systems
Any system running a Linux kernel that includes the qcom_battmgr power supply driver before the upstream patch was applied is affected. The driver contains the vulnerable code in all kernel releases that shipped with a qcom_battmgr driver and has not yet been updated with the security fix.
Risk and Exploitability
The CVSS score of 4.1 indicates low severity. The EPSS score of less than 1 % reflects a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be local, requiring privileged access to trigger the PMIC GLINK service and drive the race condition. An attacker would need to execute code in kernel context or otherwise abuse device-managed firmware confined to a local denial of service from a kernel crash.
OpenCVE Enrichment