CVE-2026-89461
Received Received - Intake

Power Supply Race Condition in Linux Kernel max17040 Driver

Vulnerability report for CVE-2026-89461, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: power: supply: max17040: synchronize work cancellation on suspend max17040_work() requeues itself after every poll. cancel_delayed_work() only cancels a pending instance and does not wait for a callback that is already running. If system suspend races with the polling callback, the callback can continue accessing the fuel gauge and requeue itself after the suspend callback returns. Use cancel_delayed_work_sync() to ensure polling is quiesced before suspend completes.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a race condition in the max17040 power supply driver. The issue occurs when the system suspends while the driver's polling callback is still running. The callback may continue accessing hardware and reschedule itself after suspend completes, potentially causing instability or crashes.

Detection Guidance

This vulnerability is specific to the Linux kernel's power supply subsystem (max17040 fuel gauge driver). Detection requires checking kernel logs for suspend/resume race conditions or kernel panics related to power management. Commands: dmesg | grep max17040, journalctl -k | grep max17040, uname -a to check kernel version.

Impact Analysis

If exploited, this flaw could lead to system crashes or unexpected behavior during suspend operations. Users might experience sudden power loss, data corruption, or system instability, particularly on devices using the max17040 fuel gauge.

Compliance Impact

This vulnerability does not directly affect compliance with standards like GDPR or HIPAA as it pertains to a race condition in the Linux kernel's power supply subsystem. No evidence suggests it impacts data protection or privacy requirements.

Mitigation Strategies

Apply the kernel patch that replaces cancel_delayed_work() with cancel_delayed_work_sync() in the max17040 driver. Update to a kernel version containing this fix. Monitor system logs for related errors after applying changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89461. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart