CVE-2026-89473

Source
https://cve.org/CVERecord?id=CVE-2026-89473
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89473.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89473
Downstream
Published
2026-09-11T19:43:31Z
Modified
2026-09-13T03:47:18Z
Summary
power: supply: bq25890: Fix power_supply reference leak
Details

In the Linux kernel, the following vulnerability has been resolved:

power: supply: bq25890: Fix power_supply reference leak

bq25890_fw_probe() acquires a reference to a secondary charger using power_supply_get_by_name(), but the reference is not released on later probe failures or on driver detach.

In particular, failures after bq25890_fw_probe() returns successfully, such as a failure in bq25890_hw_init(), also leak the reference.

Register a device-managed cleanup action immediately after acquiring the secondary charger. This releases the reference on all subsequent probe failures and on driver detach.

Found by code review.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89473.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
d54bf877fd878ee45cbc88d399fb98b0b1c4484d
Fixed
81b558afda9321c1a70971a39071d156f3e26950
Fixed
238320ad029a3eedabb86286a28cab55bca629b9
Fixed
58f1025eca92734eadc063715b98f62538286468
Fixed
863c32a83e4235eb0cbf6106f2b124e645302156

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89473.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.3.0
Fixed
6.12.109
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.50
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89473.json"