CVE-2026-89462

Source
https://cve.org/CVERecord?id=CVE-2026-89462
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89462.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89462
Downstream
Published
2026-09-11T19:43:23Z
Modified
2026-09-13T03:47:18Z
Summary
power: supply: max17040: propagate register read errors
Details

In the Linux kernel, the following vulnerability has been resolved:

power: supply: max17040: propagate register read errors

max17040_get_vcell() and max17040_get_soc() ignore errors returned by regmap_read(). When an I2C transfer fails, the uninitialized register value is converted and reported to userspace as a valid voltage or state of charge. The polling worker can also replace the cached state of charge with the bogus value and emit a spurious change event.

Propagate read errors through the power supply get_property callback and keep the last valid cached state of charge when polling fails.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89462.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
c6f4a42de60b981dd210de01cd3e575835e3158e
Fixed
2943a0edd4865ed744702ada647921c3981207f6
Fixed
13fb0477da9b400071b9d518b24d6434c4965263
Fixed
c7aa4c3708cc0d8487336f8281665eaea87130f6
Fixed
659cc3d8d5ef246263873fce72c8cadeeed073cc

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89462.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.31
Fixed
6.12.109
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.50
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89462.json"