« Volver al listado

CVE-2026-89462

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

power: supply: max17040: propagate register read errors

max17040_get_vcell() and max17040_get_soc() ignore errors returned by regmap_read(). When an I2C transfer fails, the uninitialized register value is converted and reported to userspace as a valid voltage or state of charge. The polling worker can also replace the cached state of charge with the bogus value and emit a spurious change event.

Propagate read errors through the power supply get_property callback and keep the last valid cached state of charge when polling fails.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89462",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "c6f4a42de60b981dd210de01cd3e575835e3158e",
              "lessThan": "2943a0edd4865ed744702ada647921c3981207f6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c6f4a42de60b981dd210de01cd3e575835e3158e",
              "lessThan": "13fb0477da9b400071b9d518b24d6434c4965263",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c6f4a42de60b981dd210de01cd3e575835e3158e",
              "lessThan": "c7aa4c3708cc0d8487336f8281665eaea87130f6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c6f4a42de60b981dd210de01cd3e575835e3158e",
              "lessThan": "659cc3d8d5ef246263873fce72c8cadeeed073cc",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/power/supply/max17040_battery.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.31"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "2.6.31",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.109",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.50",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/power/supply/max17040_battery.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-11T20:19:27.157",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/13fb0477da9b400071b9d518b24d6434c4965263",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2943a0edd4865ed744702ada647921c3981207f6",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/659cc3d8d5ef246263873fce72c8cadeeed073cc",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c7aa4c3708cc0d8487336f8281665eaea87130f6",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\npower: supply: max17040: propagate register read errors\n\nmax17040_get_vcell() and max17040_get_soc() ignore errors returned by\nregmap_read().  When an I2C transfer fails, the uninitialized register\nvalue is converted and reported to userspace as a valid voltage or state\nof charge.  The polling worker can also replace the cached state of charge\nwith the bogus value and emit a spurious change event.\n\nPropagate read errors through the power supply get_property callback and\nkeep the last valid cached state of charge when polling fails."
    }
  ],
  "lastModified": "2026-09-11T20:19:27.157",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}