PT-2026-83011 · Linux · Linux Kernel

CVE-2026-80711

·

Published

2026-08-28

·

Updated

2026-08-28

CVSS v4.0

2.0

Low

VectorAV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the max17040 get property() function where the driver fails to properly handle cases where no supplier power supply is registered. Because the MAX17040 does not report charger state independently, it forwards POWER SUPPLY PROP STATUS to a supplier. When no supplier is found, the power supply get property from supplier() function returns -ENODEV, but the driver ignores this error and returns success. This allows userspace to read an uninitialized status value from the battery power supply, specifically on systems using the fuel gauge without a charger supplier relationship defined in the firmware.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-80711

Affected Products

Linux Kernel