Executive brief
The MAX17040 battery fuel gauge driver in the Linux kernel can expose uninitialized data to userspace when a charger power supply is not available. Applications reading battery status may receive garbage values instead of valid charge state information, potentially causing incorrect battery management decisions on affected devices.
Technical details
The vulnerability is an information disclosure in the max17040_get_property() function within drivers/power/supply/max17040_battery.c. When querying POWER_SUPPLY_PROP_STATUS, the driver attempts to retrieve the value from a supplier power supply via power_supply_get_property_from_supplier(). If no supplier is registered, this function returns -ENODEV and leaves the output buffer untouched. The vulnerable code ignores this error and returns success, allowing userspace to read uninitialized stack or heap memory. The fix properly handles the -ENODEV return value by setting status to POWER_SUPPLY_STATUS_UNKNOWN and propagates other errors. No authentication or network access is required; any local process can read power supply properties.
Affected products
- Linux Linux kernel 6.7+
Timeline
- 2026-08-28: disclosed: CVE published
- 2026-07-21: patched: Upstream fix merged by Sebastian Reichel
- 2026-08-09: patched: Stable tree backport by Greg Kroah-Hartman