Use of Uninitialized Variable in Linux kernel - CVE-2026-80711
Published: August 28, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to use of uninitialized data in max17040_get_property() in the max17040 battery driver when handling POWER_SUPPLY_PROP_STATUS without a registered supplier power supply. A local user can read the battery power supply status from userspace to disclose sensitive information.
This occurs on systems that use the fuel gauge without a charger supplier relationship in firmware.