CVE-2026-89462

Summary

In the Linux kernel, the following vulnerability has been resolved:

power: supply: max17040: propagate register read errors

max17040_get_vcell() and max17040_get_soc() ignore errors returned by regmap_read(). When an I2C transfer fails, the uninitialized register value is converted and reported to userspace as a valid voltage or state of charge. The polling worker can also replace the cached state of charge with the bogus value and emit a spurious change event.

Propagate read errors through the power supply get_property callback and keep the last valid cached state of charge when polling fails.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxc6f4a42de60b981dd210de01cd3e575835e3158e < 2943a0edd4865ed744702ada647921c3981207f6affected
LinuxLinuxc6f4a42de60b981dd210de01cd3e575835e3158e < 13fb0477da9b400071b9d518b24d6434c4965263affected
LinuxLinuxc6f4a42de60b981dd210de01cd3e575835e3158e < c7aa4c3708cc0d8487336f8281665eaea87130f6affected
LinuxLinuxc6f4a42de60b981dd210de01cd3e575835e3158e < 659cc3d8d5ef246263873fce72c8cadeeed073ccaffected
LinuxLinux2.6.31affected
LinuxLinux0 < 2.6.31unaffected
LinuxLinux6.12.109 <= 6.12.*unaffected
LinuxLinux6.18.50 <= 6.18.*unaffected
LinuxLinux7.2.4 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References