Impact
The Linux kernel driver for the bq25890 charger contains a reference leak whereby a reference to a secondary charger is acquired during probe but not released on probe failure potentially exhausting the kernel’s reference count resources over time and causing instability or denial of service in a system that frequently reloads or fails the driver.
Affected Systems
The issue impacts Linux kernel installations that include the bq25890 power supply driver. Systems using the bq25890 charger or driving similar hardware via the power_supply subsystem are specifically affected. The vulnerability is tied to the linux_kernel CPE and applies to all versions of the driver that have not yet been patched.
Risk and Exploitability
The vulnerability has a CVSS score of 4.4, indicating a moderate level of severity. The EPSS score is < 1% and it is not listed in CISA KEV, suggesting that exploitation is not currently confirmed or widespread. The local privileged access required to load or manipulate kernel drivers; an attacker who can trigger probe failures or detachment could cause reference accumulation. Overall, while the impact could lead to resource exhaustion, the conditions for exploitation are non‑trivial and the risk remains limited under normal operating conditions.
OpenCVE Enrichment