SB20260912320 - Race condition in Linux kernel power supply driver
Published: September 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Race condition (CVE-ID: CVE-2026-89461)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause the polling callback to continue accessing the fuel gauge after system suspend.
The vulnerability exists due to improper synchronization in the max17040 fuel-gauge driver's suspend handler when system suspend races with the polling callback. A remote attacker can cause system suspend to race with the polling callback to cause the polling callback to continue accessing the fuel gauge after system suspend.
The polling work requeues itself after each poll.
Remediation
Install update from vendor's website.