Race condition in Linux kernel - CVE-2026-89461
Published: September 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause the polling callback to continue accessing the fuel gauge after system suspend.
The vulnerability exists due to improper synchronization in the max17040 fuel-gauge driver's suspend handler when system suspend races with the polling callback. A remote attacker can cause system suspend to race with the polling callback to cause the polling callback to continue accessing the fuel gauge after system suspend.
The polling work requeues itself after each poll.