---
id: CVE-2026-89462
title: >-
  kernel: power: supply: max17040: propagate register read errors
  (CVE-2026-89462)
summary: >-
  A flaw was found in the Linux kernel's power supply subsystem, specifically
  within the max17040 driver. This vulnerability occurs when the
  `max17040_get_vcell()` and `max17040_get_soc()` functions fail to properly
  handle errors returned by…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe: CWE-908
vendor: Red Hat
product: Linux
affected:
  - >-
    Linux >= c6f4a42de60b981dd210de01cd3e575835e3158e <
    2943a0edd4865ed744702ada647921c3981207f6
  - >-
    Linux >= c6f4a42de60b981dd210de01cd3e575835e3158e <
    13fb0477da9b400071b9d518b24d6434c4965263
  - >-
    Linux >= c6f4a42de60b981dd210de01cd3e575835e3158e <
    c7aa4c3708cc0d8487336f8281665eaea87130f6
  - >-
    Linux >= c6f4a42de60b981dd210de01cd3e575835e3158e <
    659cc3d8d5ef246263873fce72c8cadeeed073cc
  - Linux 2.6.31
published: '2026-09-11'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T13:23:28+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89462.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89462.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-89462'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2532447'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-89462'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89462'
  - url: >-
      https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89462.mbox
  - url: 'https://git.kernel.org/stable/c/2943a0edd4865ed744702ada647921c3981207f6'
  - url: 'https://git.kernel.org/stable/c/13fb0477da9b400071b9d518b24d6434c4965263'
  - url: 'https://git.kernel.org/stable/c/c7aa4c3708cc0d8487336f8281665eaea87130f6'
  - url: 'https://git.kernel.org/stable/c/659cc3d8d5ef246263873fce72c8cadeeed073cc'
tags:
  - csaf
  - vex
  - red-hat
  - cve.org
epss: 0.00168
epssPercentile: 0.0644
ingestedAt: '2026-09-14T00:35:28.530Z'
---

## Overview

A flaw was found in the Linux kernel's power supply subsystem, specifically within the max17040 driver. This vulnerability occurs when the `max17040_get_vcell()` and `max17040_get_soc()` functions fail to properly handle errors returned by `regmap_read()` during an I2C transfer. As a result, uninitialized register values are incorrectly interpreted and reported to the user as valid voltage or state of charge. This can lead to the system displaying inaccurate power supply information and potentially triggering misleading change events, impacting the integrity of system monitoring data.

## Vendor advisories

- **Red Hat VEX** · Moderate · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89462.json)

**kernel: power: supply: max17040: propagate register read errors** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-15.

Not affected:

- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 6
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat OpenShift Container Platform 4

## Remediation

Refer to the advisory for fix availability.
