# CVE-2026-89462

## Summary

- **CVE ID:** CVE-2026-89462
- **Severity:** UNKNOWN
- **CVSS Score:** 0
- **CWE:** N/A
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 16, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

power: supply: max17040: propagate register read errors

max17040_get_vcell() and max17040_get_soc() ignore errors returned by
regmap_read().  When an I2C transfer fails, the uninitialized register
value is converted and reported to userspace as a valid voltage or state
of charge.  The polling worker can also replace the cached state of charge
with the bogus value and emit a spurious change event.

Propagate read errors through the power supply get_property callback and
keep the last valid cached state of charge when polling fails.

## Affected Products

- Linux — Linux (c6f4a42de60b981dd210de01cd3e575835e3158e)
- Linux — Linux (2.6.31)
- Linux — Linux (0)
- Linux — Linux (6.12.109)
- Linux — Linux (6.18.50)
- Linux — Linux (7.2.4)
- Linux — Linux (7.3-rc1)

## References

- [CNA](https://git.kernel.org/stable/c/2943a0edd4865ed744702ada647921c3981207f6)
- [CNA](https://git.kernel.org/stable/c/13fb0477da9b400071b9d518b24d6434c4965263)
- [CNA](https://git.kernel.org/stable/c/c7aa4c3708cc0d8487336f8281665eaea87130f6)
- [CNA](https://git.kernel.org/stable/c/659cc3d8d5ef246263873fce72c8cadeeed073cc)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.17%
- **EPSS Percentile:** 6.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._