UNKNOWN NVD
CVE-2026-89466
In the Linux kernel, the following vulnerability has been resolved: power: supply: qcom_battmgr: terminate the strings from firmware The qcom_battmgr_sc8280xp
In the Linux kernel, the following vulnerability has been resolved:
power: supply: qcom_battmgr: terminate the strings from firmware
The qcom_battmgr_sc8280xp_strcpy() takes a Pascal-style string when the
firmware sends one. Otherwise it copies all BATTMGR_STRING_LEN bytes and
leaves the destination without a terminator.
Those destinations are model_number, serial_number and oem_info, each
BATTMGR_STRING_LEN and declared next to each other. They go out to user
space as val->strval, which power_supply_format_property() prints with
"%s", so a firmware string that fills the whole field makes that read run
into the following members.
Use strscpy() so the copy always terminates, the way the SM8350 path
already does for the same field.
References
- https://git.kernel.org/stable/c/0e70a9b0d16acf7adebc4f386178a95da27c0027
- https://git.kernel.org/stable/c/6cc6c28c9ab6e8ecf901397717a5b391b828cdaf
- https://git.kernel.org/stable/c/ab1112df8f4ffa88cb024dd370c432ced80f77d8
- https://git.kernel.org/stable/c/ee053561e21ce1e1741dd64ca5ddcdb92e40edc1
This unknown severity vulnerability was published on 2026-09-11 via NVD.
vulnfeed aggregates 12842 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.