Executive brief
A vulnerability was identified in the Linux kernel's power management subsystem for certain Qualcomm battery monitoring hardware. This flaw could allow the system to crash or experience memory corruption when the battery driver is being initialized or removed. In practice, this could lead to unexpected system instability or denial of service on affected mobile or embedded devices.
Technical details
A use-after-free vulnerability exists in the pm8916_bms_vm power supply driver due to improper ordering of resource allocation using the devm_ framework. The driver requested an interrupt (IRQ) before registering the power_supply handle. Because devm_ releases resources in reverse order of allocation, the power_supply handle would be freed before the IRQ handler was unregistered during driver removal. This creates a race condition where an interrupt firing after the handle is freed causes the IRQ handler to call power_supply_changed() with a stale pointer. A similar race exists during the probe() phase where an interrupt could fire before the handle is fully initialized. The fix reorders the allocation so the IRQ is requested only after the power_supply handle is registered.
Affected products
- Linux Linux Kernel Fixed in 6.1.x, 6.6.x, 6.12.x, and mainline
Timeline
- 2025-12-20: other: Patch authored
- 2026-05-27: advisory: CVE published by NVD