Improper Null Termination in Linux kernel - CVE-2026-89466
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to improper null termination in qcom_battmgr_sc8280xp_strcpy() when copying non-Pascal-style strings from firmware. A local user can read exposed power supply properties containing a full-length firmware string to disclose sensitive information.
The affected fields are model_number, serial_number, and oem_info.