CVE-2026-72214

Updated on 15 Aug 2026

Severity

Awaiting Analysis

Details

Overview

About vulnerability

In the Linux kernel, the following vulnerability has been resolved:

power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak

In cpcap_battery_detect_battery_type(), the reference to an nvmem device obtained via nvmem_device_find() is not released with nvmem_device_put() on the success or read-failure paths, causing a permanent reference leak. The driver’s retry logic on subsequent battery property reads can compound this leak, preventing the nvmem device from ever being freed.

Found by code review.

Details

Affected product:
Debian 10 ELS
Affected packages:
linux @ 4.19.0

Fixes