Linux Kernel Vulnerability in Power Supply Management Affecting MAX17040 Charger State Reporting
CVE-2026-80711
What is CVE-2026-80711?
In the Linux kernel's power management system, the MAX17040 fuel gauge presents a risk by failing to accurately report charger states when a supplier is not registered. This mismanagement allows the system to return an uninitialized battery status value, potentially leading to erroneous readings in userspace. The driver is designed to forward battery status to a supplier power supply, but without a registered supplier, it leaves the output value unchanged. To mitigate this issue, the updated mechanism now returns POWER_SUPPLY_STATUS_UNKNOWN when no supplier provides the status, thus ensuring that other errors in supplier lookups are correctly propagated.
Affected Version(s)
Linux f4b782af61ae7bbf93008d5809b0e3a8ac2bb88e < 91ac995a6f4ddf4f92b231b080544abf23a9b871
Linux f4b782af61ae7bbf93008d5809b0e3a8ac2bb88e
Linux f4b782af61ae7bbf93008d5809b0e3a8ac2bb88e