{"id":"CVE-2026-89467","title":"kernel: power: supply: qcom_battmgr: fix use-after-free (CVE-2026-89467)","summary":"A flaw was found in the Linux kernel's `qcom_battmgr` component. This flaw is a use-after-free vulnerability that occurs because the `qcom_battmgr_pdr_notify()` function can queue `enable_work` even after the associated `battmgr` object ha…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-825","vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","affected":["openshift_container_platform 4"],"published":"2026-09-11","updated":"2026-09-17","sourceUpdated":"2026-09-17T20:12:21+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89467.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89467.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89467"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532106"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89467"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89467"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89467.mbox"},{"url":"https://git.kernel.org/stable/c/06618447029c6dddaa02f6e9528efe5dd49fc329"},{"url":"https://git.kernel.org/stable/c/49fbcd3da2958159370d25dafbf736e654a4d59b"},{"url":"https://git.kernel.org/stable/c/4e40befedfc8ed86f44e1f81df92d13c149c9f8d"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.00166,"epssPercentile":0.06263,"ingestedAt":"2026-09-14T00:35:28.530Z","slug":"CVE-2026-89467","body":"## Overview\n\nA flaw was found in the Linux kernel's `qcom_battmgr` component. This flaw is a use-after-free vulnerability that occurs because the `qcom_battmgr_pdr_notify()` function can queue `enable_work` even after the associated `battmgr` object has been deallocated. A local attacker could exploit this by triggering the PMIC GLINK service to come up, leading to the `enable_work` accessing freed memory. This could result in a denial of service or potentially lead to arbitrary code execution.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · updated 2026-09-17 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89467.json)\n\n**kernel: power: supply: qcom_battmgr: fix use-after-free** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-17.\n\nNot affected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nRefer to the advisory for fix availability.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":206989,"id":"CVE-2026-89467","ts":1789749735415,"field":"cvss","old":"4.1","new":"5.5"},{"seq":204103,"id":"CVE-2026-89467","ts":1789490231448,"field":"cvss","old":null,"new":"4.1"},{"seq":204102,"id":"CVE-2026-89467","ts":1789490231448,"field":"severity","old":"none","new":"medium"},{"seq":147806,"id":"CVE-2026-89467","ts":1789270212363,"field":"cvss","old":null,"new":"4.1"},{"seq":147805,"id":"CVE-2026-89467","ts":1789270212363,"field":"severity","old":"none","new":"medium"},{"seq":109560,"id":"CVE-2026-89467","ts":1789183732416,"field":"cvss","old":null,"new":"4.1"},{"seq":109559,"id":"CVE-2026-89467","ts":1789183732416,"field":"severity","old":"none","new":"medium"}]}