CVE-2026-89473

Summary

In the Linux kernel, the following vulnerability has been resolved:

power: supply: bq25890: Fix power_supply reference leak

bq25890_fw_probe() acquires a reference to a secondary charger using power_supply_get_by_name(), but the reference is not released on later probe failures or on driver detach.

In particular, failures after bq25890_fw_probe() returns successfully, such as a failure in bq25890_hw_init(), also leak the reference.

Register a device-managed cleanup action immediately after acquiring the secondary charger. This releases the reference on all subsequent probe failures and on driver detach.

Found by code review.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxd54bf877fd878ee45cbc88d399fb98b0b1c4484d < 81b558afda9321c1a70971a39071d156f3e26950affected
LinuxLinuxd54bf877fd878ee45cbc88d399fb98b0b1c4484d < 238320ad029a3eedabb86286a28cab55bca629b9affected
LinuxLinuxd54bf877fd878ee45cbc88d399fb98b0b1c4484d < 58f1025eca92734eadc063715b98f62538286468affected
LinuxLinuxd54bf877fd878ee45cbc88d399fb98b0b1c4484d < 863c32a83e4235eb0cbf6106f2b124e645302156affected
LinuxLinux6.3affected
LinuxLinux0 < 6.3unaffected
LinuxLinux6.12.109 <= 6.12.*unaffected
LinuxLinux6.18.50 <= 6.18.*unaffected
LinuxLinux7.2.4 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References