In the Linux kernel, the following vulnerability has been resolved: power: supply: max17040: propagate register read errors max17040_get_vcell() and… (CVE-2026-89462)
A vulnerability in the Linux kernel's power supply driver for the max17040 device caused register read errors to be ignored. Specifically, the functions max17040_get_vcell() and max17040_get_soc() did not handle errors from regmap_read(), leading to uninitialized register values being reported as valid voltage or state of charge. This could result in incorrect values being propagated to userspace and spurious change events being emitted. The issue has been resolved by propagating read errors properly and retaining the last valid cached state when polling fails.
AI Analysis
Technical Summary
The Linux kernel's max17040 power supply driver had a flaw where register read errors from I2C transfers were ignored by max17040_get_vcell() and max17040_get_soc(). This caused uninitialized register values to be interpreted as valid data, potentially misleading userspace applications with incorrect voltage or state of charge readings. Additionally, the polling worker could overwrite cached state with invalid data and trigger false change events. The fix involves propagating read errors through the power supply get_property callback and preserving the last valid cached state when polling encounters failures.
Potential Impact
Incorrect voltage or state of charge data could be reported to userspace, potentially causing misinterpretation of device power status. Spurious change events may also be emitted, which could affect power management or monitoring systems relying on accurate data. There is no indication of direct security compromise or exploitation in the wild.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to propagate register read errors properly and maintain the last valid cached state when polling fails. Users should update to the fixed kernel version once available. Patch status is not explicitly stated in the provided data; check the official Linux kernel advisories or vendor sources for the exact fixed versions and update guidance.
In the Linux kernel, the following vulnerability has been resolved: power: supply: max17040: propagate register read errors max17040_get_vcell() and… (CVE-2026-89462)
Description
A vulnerability in the Linux kernel's power supply driver for the max17040 device caused register read errors to be ignored. Specifically, the functions max17040_get_vcell() and max17040_get_soc() did not handle errors from regmap_read(), leading to uninitialized register values being reported as valid voltage or state of charge. This could result in incorrect values being propagated to userspace and spurious change events being emitted. The issue has been resolved by propagating read errors properly and retaining the last valid cached state when polling fails.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel's max17040 power supply driver had a flaw where register read errors from I2C transfers were ignored by max17040_get_vcell() and max17040_get_soc(). This caused uninitialized register values to be interpreted as valid data, potentially misleading userspace applications with incorrect voltage or state of charge readings. Additionally, the polling worker could overwrite cached state with invalid data and trigger false change events. The fix involves propagating read errors through the power supply get_property callback and preserving the last valid cached state when polling encounters failures.
Potential Impact
Incorrect voltage or state of charge data could be reported to userspace, potentially causing misinterpretation of device power status. Spurious change events may also be emitted, which could affect power management or monitoring systems relying on accurate data. There is no indication of direct security compromise or exploitation in the wild.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to propagate register read errors properly and maintain the last valid cached state when polling fails. Users should update to the fixed kernel version once available. Patch status is not explicitly stated in the provided data; check the official Linux kernel advisories or vendor sources for the exact fixed versions and update guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-2jg4-h8v3-7354
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-89462"]
Threat ID: 6aa4a02255bf5e2cf5a869a5
Added to database: 09/12/2026, 00:43:14 UTC
Last enriched: 09/12/2026, 01:16:26 UTC
Last updated: 09/12/2026, 01:16:26 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.