---
cve: "CVE-2026-89462"
severity: "LOW"
cvss: 3.1
epss: "17%"
vendor: "Linux"
kev: false
exploited: false
published: "2026-09-11 20:19:27"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-18T23:17:15+02:00"
---

# CVE-2026-89462

> 3.1 LOW

## Beschreibung

In the Linux kernel, the following vulnerability has been resolved:

power: supply: max17040: propagate register read errors

max17040_get_vcell() and max17040_get_soc() ignore errors returned by
regmap_read().  When an I2C transfer fails, the uninitialized register
value is converted and reported to userspace as a valid voltage or state
of charge.  The polling worker can also replace the cached state of charge
with the bogus value and emit a spurious change event.

Propagate read errors through the power supply get_property callback and
keep the last valid cached state of charge when polling fails.

## Patch verfügbar (OSV)

- Kernel ≥ 6.12.109
- Kernel ≥ 6.18.50
- Kernel ≥ 7.2.4

## Referenzen

- <https://git.kernel.org/stable/c/2943a0edd4865ed744702ada647921c3981207f6>
- <https://git.kernel.org/stable/c/13fb0477da9b400071b9d518b24d6434c4965263>
- <https://git.kernel.org/stable/c/c7aa4c3708cc0d8487336f8281665eaea87130f6>
- <https://git.kernel.org/stable/c/659cc3d8d5ef246263873fce72c8cadeeed073cc>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-89462) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
