Race condition in Linux kernel - CVE-2026-89461

 

Race condition in Linux kernel - CVE-2026-89461

Published: September 12, 2026


Vulnerability identifier: #VU149342
CSH Severity: Low
CVSS v4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-89461
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause the polling callback to continue accessing the fuel gauge after system suspend.

The vulnerability exists due to improper synchronization in the max17040 fuel-gauge driver's suspend handler when system suspend races with the polling callback. A remote attacker can cause system suspend to race with the polling callback to cause the polling callback to continue accessing the fuel gauge after system suspend.

The polling work requeues itself after each poll.


Affected software

Linux kernel

How to mitigate CVE-2026-89461

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins