CVE-2026-89462
In the Linux kernel, the following vulnerability has been resolved: power: supply: max17040: propagate register read errors max17040_get_vcell() and max17040_get_soc() ignore errors returned by regmap_read(). When an I2C transfer fails, the uninitialized register value is converted and reported to userspace as a valid voltage or state of charge. The polling worker can also replace the cached state of charge with the bogus value and emit a spurious change event. Propagate read errors through the power supply get_property callback and keep the last valid cached state of charge when polling fails.
Scoring
- CVSS base score
- 0
- EPSS probability
- 0.17%
- Published
- 2026-09-11
- Last modified
- 2026-09-16
Affected products
- Linux Linux
- Linux Linux
- Linux Linux
- Linux Linux
- Linux Linux
- Linux Linux
- Linux Linux