CVE-2026-80711

Source
https://cve.org/CVERecord?id=CVE-2026-80711
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80711.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-80711
Downstream
Published
2026-08-28T06:53:10.631Z
Modified
2026-08-30T03:48:22.730789515Z
Summary
power: supply: max17040: handle missing status supplier
Details

In the Linux kernel, the following vulnerability has been resolved:

power: supply: max17040: handle missing status supplier

MAX17040 does not report charger state itself, so the driver forwards POWERSUPPLYPROPSTATUS to a supplier power supply. If no supplier is registered, powersupplygetpropertyfromsupplier() returns -ENODEV and leaves the output value untouched.

max17040getproperty() currently ignores that error and returns success, so userspace can read an uninitialized status value from the battery power supply. This happens on systems that use the fuel gauge without a charger supplier relationship in firmware.

Return POWERSUPPLYSTATUS_UNKNOWN when no supplier provides STATUS, and propagate other supplier lookup errors.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80711.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
f4b782af61ae7bbf93008d5809b0e3a8ac2bb88e
Fixed
91ac995a6f4ddf4f92b231b080544abf23a9b871
Fixed
b039f13e095d28a64ca6b21d0ee5440d8b048f37
Fixed
ee2ea0c452edc0930e7395b080dccd5a1cb965e1
Fixed
725668c6b6aa3971fe850659102c250d0d676e18

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80711.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.103
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.44
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80711.json"