Impact
The bq25890 firmware probe function acquires a reference to a secondary charger via power_supply or the driver is detached. This results in a cumulative increase in the reference count held by the kernel object, gradually exhausting the limited reference count resources that the power_supply subsystem tracks. Over time, the accumulation can destabilize the kernel or trigger a denial‑of‑service if the reference count overflows or the subsystem cannot manage the leaked reference. This flaw corresponds to CWE-772, a reference count leak.
Affected Systems
Systems running the Linux kernel with the bq. The issue applies to any kernel that includes the unpatched driver code and uses a device that interacts with the BQ25890 charger via the power_supply subsystem.
Risk and Exploitability
The CVSS score of 4.4 classifies the flaw as moderate; the EPSS score of less than 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in CISA KEV. The problem is local and requires the ability to load or restart the driver, which normally requires privileged or root access. An attacker who can cause probe failures or detach the driver could trigger the reference accumulation, but the threat to production systems is limited unless the device experiences frequent driver reloads or errors. Based on the description, it is inferred that the attack requires local privileged access to the kernel.
OpenCVE Enrichment
Debian DSA