Description
In the Linux kernel, the following vulnerability has been resolved:

power: supply: bq25890: Fix power_supply reference leak

bq25890_fw_probe() acquires a reference to a secondary charger using
power_supply_get_by_name(), but the reference is not released on later
probe failures or on driver detach.

In particular, failures after bq25890_fw_probe() returns successfully,
such as a failure in bq25890_hw_init(), also leak the reference.

Register a device-managed cleanup action immediately after acquiring
the secondary charger. This releases the reference on all subsequent
probe failures and on driver detach.

Found by code review.
Published: 2026-09-11
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Resource Leak (potential memory/resource exhaustion)
Action: Assess Impact
AI Analysis

Impact

The Linux kernel driver for the bq25890 charger contains a reference leak whereby a reference to a secondary charger is acquired during probe but not released on probe failure potentially exhausting the kernel’s reference count resources over time and causing instability or denial of service in a system that frequently reloads or fails the driver.

Affected Systems

The issue impacts Linux kernel installations that include the bq25890 power supply driver. Systems using the bq25890 charger or driving similar hardware via the power_supply subsystem are specifically affected. The vulnerability is tied to the linux_kernel CPE and applies to all versions of the driver that have not yet been patched.

Risk and Exploitability

The vulnerability has a CVSS score of 4.4, indicating a moderate level of severity. The EPSS score is < 1% and it is not listed in CISA KEV, suggesting that exploitation is not currently confirmed or widespread. The local privileged access required to load or manipulate kernel drivers; an attacker who can trigger probe failures or detachment could cause reference accumulation. Overall, while the impact could lead to resource exhaustion, the conditions for exploitation are non‑trivial and the risk remains limited under normal operating conditions.

Generated by OpenCVE AI on September 13, 2026 at 03:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the stated patch for the bq25890 driver.
  • Consult the vendor’s release notes or patch notes to confirm that the reference leak is fixed and apply any vendor‑supplied backport patches if you cannot upgrade the entire kernel.
  • If an immediate kernel update is infeasible, consider disabling the bq25890 charging driver or preventing probe operations to eliminate the leak path.
  • Monitor kernel logs (dmesg, syslog) for repeated power_supply reference leak messages and verify that the reference count stabilizes after any updates or changes.

Generated by OpenCVE AI on September 13, 2026 at 03:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: power: supply: bq25890: Fix power_supply reference leak bq25890_fw_probe() acquires a reference to a secondary charger using power_supply_get_by_name(), but the reference is not released on later probe failures or on driver detach. In particular, failures after bq25890_fw_probe() returns successfully, such as a failure in bq25890_hw_init(), also leak the reference. Register a device-managed cleanup action immediately after acquiring the secondary charger. This releases the reference on all subsequent probe failures and on driver detach. Found by code review.
Title power: supply: bq25890: Fix power_supply reference leak
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:43:31.214Z

Reserved: 2026-09-11T19:38:34.710Z

Link: CVE-2026-89473

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:28.530

Modified: 2026-09-11T20:19:28.530

Link: CVE-2026-89473

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:43:31Z

Links: CVE-2026-89473 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T03:45:18Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime