{"id":"CVE-2026-89466","summary":"power: supply: qcom_battmgr: terminate the strings from firmware","details":"In the Linux kernel, the following vulnerability has been resolved:\n\npower: supply: qcom_battmgr: terminate the strings from firmware\n\nThe qcom_battmgr_sc8280xp_strcpy() takes a Pascal-style string when the\nfirmware sends one. Otherwise it copies all BATTMGR_STRING_LEN bytes and\nleaves the destination without a terminator.\n\nThose destinations are model_number, serial_number and oem_info, each\nBATTMGR_STRING_LEN and declared next to each other. They go out to user\nspace as val-\u003estrval, which power_supply_format_property() prints with\n\"%s\", so a firmware string that fills the whole field makes that read run\ninto the following members.\n\nUse strscpy() so the copy always terminates, the way the SM8350 path\nalready does for the same field.","modified":"2026-09-13T03:47:18.183157083Z","published":"2026-09-11T19:43:26.621Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89466.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/0e70a9b0d16acf7adebc4f386178a95da27c0027"},{"type":"WEB","url":"https://git.kernel.org/stable/c/6cc6c28c9ab6e8ecf901397717a5b391b828cdaf"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ab1112df8f4ffa88cb024dd370c432ced80f77d8"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ee053561e21ce1e1741dd64ca5ddcdb92e40edc1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89466.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89466"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"29e8142b5623b5949587bcc4f591c4e6595c4aca"},{"fixed":"0e70a9b0d16acf7adebc4f386178a95da27c0027"},{"fixed":"ee053561e21ce1e1741dd64ca5ddcdb92e40edc1"},{"fixed":"6cc6c28c9ab6e8ecf901397717a5b391b828cdaf"},{"fixed":"ab1112df8f4ffa88cb024dd370c432ced80f77d8"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89466.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.3.0"},{"fixed":"6.12.109"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.50"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.2.4"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89466.json"}}],"schema_version":"1.9.0"}