Unchecked Return Value in Linux kernel - CVE-2026-89462
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to cause power-supply properties to report incorrect voltage or state-of-charge values.
The vulnerability exists due to improper error handling in the max17040 power supply driver when an I2C register read fails. A local user can access power-supply properties during a failed I2C register read to cause power-supply properties to report incorrect voltage or state-of-charge values.
A polling worker may replace the cached state of charge with an invalid value and emit a spurious change event.