PT-2026-90177 · Linux · Linux

CVE-2026-89461

·

Published

2026-09-11

·

Updated

2026-09-11

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
power: supply: max17040: synchronize work cancellation on suspend
max17040 work() requeues itself after every poll. cancel delayed work() only cancels a pending instance and does not wait for a callback that is already running.
If system suspend races with the polling callback, the callback can continue accessing the fuel gauge and requeue itself after the suspend callback returns.
Use cancel delayed work sync() to ensure polling is quiesced before suspend completes.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-89461

Affected Products

Linux