{"id":"CVE-2026-89462","title":"kernel: power: supply: max17040: propagate register read errors (CVE-2026-89462)","summary":"A flaw was found in the Linux kernel's power supply subsystem, specifically within the max17040 driver. This vulnerability occurs when the `max17040_get_vcell()` and `max17040_get_soc()` functions fail to properly handle errors returned by…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-908","vendor":"Red Hat","product":"Linux","affected":["Linux >= c6f4a42de60b981dd210de01cd3e575835e3158e < 2943a0edd4865ed744702ada647921c3981207f6","Linux >= c6f4a42de60b981dd210de01cd3e575835e3158e < 13fb0477da9b400071b9d518b24d6434c4965263","Linux >= c6f4a42de60b981dd210de01cd3e575835e3158e < c7aa4c3708cc0d8487336f8281665eaea87130f6","Linux >= c6f4a42de60b981dd210de01cd3e575835e3158e < 659cc3d8d5ef246263873fce72c8cadeeed073cc","Linux 2.6.31"],"published":"2026-09-11","updated":"2026-09-15","sourceUpdated":"2026-09-15T13:23:28+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89462.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89462.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89462"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532447"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89462"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89462"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89462.mbox"},{"url":"https://git.kernel.org/stable/c/2943a0edd4865ed744702ada647921c3981207f6"},{"url":"https://git.kernel.org/stable/c/13fb0477da9b400071b9d518b24d6434c4965263"},{"url":"https://git.kernel.org/stable/c/c7aa4c3708cc0d8487336f8281665eaea87130f6"},{"url":"https://git.kernel.org/stable/c/659cc3d8d5ef246263873fce72c8cadeeed073cc"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.00168,"epssPercentile":0.06449,"ingestedAt":"2026-09-14T00:35:28.530Z","slug":"CVE-2026-89462","body":"## Overview\n\nA flaw was found in the Linux kernel's power supply subsystem, specifically within the max17040 driver. This vulnerability occurs when the `max17040_get_vcell()` and `max17040_get_soc()` functions fail to properly handle errors returned by `regmap_read()` during an I2C transfer. As a result, uninitialized register values are incorrectly interpreted and reported to the user as valid voltage or state of charge. This can lead to the system displaying inaccurate power supply information and potentially triggering misleading change events, impacting the integrity of system monitoring data.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89462.json)\n\n**kernel: power: supply: max17040: propagate register read errors** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-15.\n\nNot affected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nRefer to the advisory for fix availability.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":203871,"id":"CVE-2026-89462","ts":1789490210435,"field":"cvss","old":null,"new":"5.5"},{"seq":203870,"id":"CVE-2026-89462","ts":1789490210435,"field":"severity","old":"none","new":"medium"},{"seq":147181,"id":"CVE-2026-89462","ts":1789270199411,"field":"cvss","old":null,"new":"5.3"},{"seq":147180,"id":"CVE-2026-89462","ts":1789270199411,"field":"severity","old":"none","new":"medium"},{"seq":108932,"id":"CVE-2026-89462","ts":1789183729600,"field":"cvss","old":null,"new":"5.3"},{"seq":108931,"id":"CVE-2026-89462","ts":1789183729600,"field":"severity","old":"none","new":"medium"}]}