Executive brief
A vulnerability was identified in the Linux kernel's battery management driver for Smart Battery System (SBS) devices. Due to a technical error in how the system starts and stops the driver, a race condition can occur where the system tries to process a battery update after the necessary memory has already been cleared. This can lead to system crashes or memory corruption, potentially impacting the stability and reliability of devices using these batteries.
Technical details
A use-after-free vulnerability exists in the sbs-battery driver (drivers/power/supply/sbs-battery.c) due to improper ordering of managed resource (devm_) allocations. The driver requested an IRQ before registering the power_supply handle; because devm_ resources are released in reverse order of allocation, the power_supply handle was being freed before the IRQ handler was unregistered during driver removal. This creates a race condition where an interrupt firing after the handle is freed causes power_supply_changed() to be called with a stale pointer. A similar race exists during probe() where an interrupt could fire before the handle is fully initialized. The fix reorders the calls to ensure the IRQ is requested only after the power_supply handle is registered.
Affected products
- Linux Linux kernel All versions prior to the fix in the sbs-battery driver
Timeline
- 2025-12-20: other: Patch authored
- 2026-05-27: advisory: NVD publication date
- 2026-05-27: patched: Fixes merged into stable branches
References
- https://git.kernel.org/stable/c/14d4dee5d8fb361bfff275832087254beab66d72
- https://git.kernel.org/stable/c/2078830c32d1e49ac942c6f8c21f35c806ae5e94
- https://git.kernel.org/stable/c/8010b745b436c3e1ca5dd960aa29fa3e0f6d8841
- https://git.kernel.org/stable/c/82d3eb97a976c9d56bb92b241397610e57a9c629
- https://git.kernel.org/stable/c/861dda7a9074c0ff67788928165ae39d7f647491
- https://git.kernel.org/stable/c/8d59cf3887fbabacef53bfba473e33e8a8d9d07b
- https://git.kernel.org/stable/c/ca7dd71773e4e050b0fb98768b7eae60f8d1f38b