GHSA-m52x-f225-mf2cunknown
In the Linux kernel, the following vulnerability has been resolved: power: supply: cpcap-battery...
🔗 CVE IDs covered (1)
📋 Description
In the Linux kernel, the following vulnerability has been resolved:
power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak
In cpcap_battery_detect_battery_type(), the reference to an nvmem device obtained via nvmem_device_find() is not released with nvmem_device_put() on the success or read-failure paths, causing a permanent reference leak. The driver’s retry logic on subsequent battery property reads can compound this leak, preventing the nvmem device from ever being freed.
Found by code review.
🔗 References (8)
- https://nvd.nist.gov/vuln/detail/CVE-2026-72214
- https://git.kernel.org/stable/c/700c225d829a1256b59053c34a1a9d1a6ab70b09
- https://git.kernel.org/stable/c/a2c14ff63e0e02e3c832385e523e9cc81301171c
- https://git.kernel.org/stable/c/a3d81de441233a92ec21469cd0c4eb3c26b95cd8
- https://git.kernel.org/stable/c/b56a5cbf8f1f1a5740f1137c89b14d0373309d8d
- https://git.kernel.org/stable/c/deaf6b3f8187231ad8f7770b10ed0be2cd47e9b2
- https://git.kernel.org/stable/c/fc65520fe0781a1ff46631f111e07b4a1c677b96
- https://github.com/advisories/GHSA-m52x-f225-mf2c