SB20260912320 - Race condition in Linux kernel power supply driver



SB20260912320 - Race condition in Linux kernel power supply driver

Published: September 12, 2026

Security Bulletin ID SB20260912320
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Race condition (CVE-ID: CVE-2026-89461)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause the polling callback to continue accessing the fuel gauge after system suspend.

The vulnerability exists due to improper synchronization in the max17040 fuel-gauge driver's suspend handler when system suspend races with the polling callback. A remote attacker can cause system suspend to race with the polling callback to cause the polling callback to continue accessing the fuel gauge after system suspend.

The polling work requeues itself after each poll.


Remediation

Install update from vendor's website.