-

CVE-2026-80711

power: supply: max17040: handle missing status supplier

In the Linux kernel, the following vulnerability has been resolved:

power: supply: max17040: handle missing status supplier

MAX17040 does not report charger state itself, so the driver forwards
POWER_SUPPLY_PROP_STATUS to a supplier power supply. If no supplier is
registered, power_supply_get_property_from_supplier() returns -ENODEV and
leaves the output value untouched.

max17040_get_property() currently ignores that error and returns success,
so userspace can read an uninitialized status value from the battery power
supply. This happens on systems that use the fuel gauge without a charger
supplier relationship in firmware.

Return POWER_SUPPLY_STATUS_UNKNOWN when no supplier provides STATUS, and
propagate other supplier lookup errors.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version f4b782af61ae7bbf93008d5809b0e3a8ac2bb88e
Version < 91ac995a6f4ddf4f92b231b080544abf23a9b871
Status affected
Version f4b782af61ae7bbf93008d5809b0e3a8ac2bb88e
Version < b039f13e095d28a64ca6b21d0ee5440d8b048f37
Status affected
Version f4b782af61ae7bbf93008d5809b0e3a8ac2bb88e
Version < ee2ea0c452edc0930e7395b080dccd5a1cb965e1
Status affected
Version f4b782af61ae7bbf93008d5809b0e3a8ac2bb88e
Version < 725668c6b6aa3971fe850659102c250d0d676e18
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.7
Status affected
Version 0
Version < 6.7
Status unaffected
Version <= 6.12.*
Version 6.12.103
Status unaffected
Version <= 6.18.*
Version 6.18.44
Status unaffected
Version <= 7.1.*
Version 7.1.8
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.051
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/91ac995a6f4ddf4f92b231b080544abf23a9b871
https://git.kernel.org/stable/c/b039f13e095d28a64ca6b21d0ee5440d8b048f37
https://git.kernel.org/stable/c/ee2ea0c452edc0930e7395b080dccd5a1cb965e1
https://git.kernel.org/stable/c/725668c6b6aa3971fe850659102c250d0d676e18