---
cve: "CVE-2026-80711"
severity: "LOW"
cvss: 3.1
epss: "2.3%"
vendor: "Linux"
kev: false
exploited: false
published: "2026-08-28 08:16:56"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-03T02:20:47+02:00"
---

# CVE-2026-80711

> 3.1 LOW

## Beschreibung

In the Linux kernel, the following vulnerability has been resolved:

power: supply: max17040: handle missing status supplier

MAX17040 does not report charger state itself, so the driver forwards
POWER_SUPPLY_PROP_STATUS to a supplier power supply. If no supplier is
registered, power_supply_get_property_from_supplier() returns -ENODEV and
leaves the output value untouched.

max17040_get_property() currently ignores that error and returns success,
so userspace can read an uninitialized status value from the battery power
supply. This happens on systems that use the fuel gauge without a charger
supplier relationship in firmware.

Return POWER_SUPPLY_STATUS_UNKNOWN when no supplier provides STATUS, and
propagate other supplier lookup errors.

## Patch verfügbar (OSV)

- Kernel ≥ 6.12.103
- Kernel ≥ 6.18.44
- Kernel ≥ 7.1.8

## Referenzen

- <https://git.kernel.org/stable/c/91ac995a6f4ddf4f92b231b080544abf23a9b871>
- <https://git.kernel.org/stable/c/b039f13e095d28a64ca6b21d0ee5440d8b048f37>
- <https://git.kernel.org/stable/c/ee2ea0c452edc0930e7395b080dccd5a1cb965e1>
- <https://git.kernel.org/stable/c/725668c6b6aa3971fe850659102c250d0d676e18>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-80711) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
