Description
In the Linux kernel, the following vulnerability has been resolved:

power: supply: bq25890: Fix power_supply reference leak

bq25890_fw_probe() acquires a reference to a secondary charger using
power_supply_get_by_name(), but the reference is not released on later
probe failures or on driver detach.

In particular, failures after bq25890_fw_probe() returns successfully,
such as a failure in bq25890_hw_init(), also leak the reference.

Register a device-managed cleanup action immediately after acquiring
the secondary charger. This releases the reference on all subsequent
probe failures and on driver detach.

Found by code review.
Published: 2026-09-11
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Reference Leak in the bq25890 power supply driver can cause resource exhaustion in the kernel
Action: Apply Patch
AI Analysis

Impact

The bq25890 firmware probe function acquires a reference to a secondary charger via power_supply or the driver is detached. This results in a cumulative increase in the reference count held by the kernel object, gradually exhausting the limited reference count resources that the power_supply subsystem tracks. Over time, the accumulation can destabilize the kernel or trigger a denial‑of‑service if the reference count overflows or the subsystem cannot manage the leaked reference. This flaw corresponds to CWE-772, a reference count leak.

Affected Systems

Systems running the Linux kernel with the bq. The issue applies to any kernel that includes the unpatched driver code and uses a device that interacts with the BQ25890 charger via the power_supply subsystem.

Risk and Exploitability

The CVSS score of 4.4 classifies the flaw as moderate; the EPSS score of less than 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in CISA KEV. The problem is local and requires the ability to load or restart the driver, which normally requires privileged or root access. An attacker who can cause probe failures or detach the driver could trigger the reference accumulation, but the threat to production systems is limited unless the device experiences frequent driver reloads or errors. Based on the description, it is inferred that the attack requires local privileged access to the kernel.

Generated by OpenCVE AI on September 21, 2026 at 01:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a Linux kernel that incorporates the patch for the bq25890 driver
  • If a full kernel upgrade is not possible, apply a vendor‑supplied backport or patch that implements the device‑managed cleanup for the secondary charger reference
  • If the driver is unnecessary, disable it or prevent the kernel from probing the bq firmware from the system

Generated by OpenCVE AI on September 21, 2026 at 01:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: power: supply: bq25890: Fix power_supply reference leak bq25890_fw_probe() acquires a reference to a secondary charger using power_supply_get_by_name(), but the reference is not released on later probe failures or on driver detach. In particular, failures after bq25890_fw_probe() returns successfully, such as a failure in bq25890_hw_init(), also leak the reference. Register a device-managed cleanup action immediately after acquiring the secondary charger. This releases the reference on all subsequent probe failures and on driver detach. Found by code review.
Title power: supply: bq25890: Fix power_supply reference leak
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:00:09.611Z

Reserved: 2026-09-11T19:38:34.710Z

Link: CVE-2026-89473

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:28.530

Modified: 2026-09-14T13:19:03.620

Link: CVE-2026-89473

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:43:31Z

Links: CVE-2026-89473 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T01:15:03Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime