Executive brief
The Linux kernel's MAX17040 fuel gauge driver contains a race condition during system suspend. The polling callback can continue running and requeue itself after the suspend operation completes, potentially accessing hardware in an inconsistent state. This could cause system stability issues or prevent proper suspension.
Technical details
The vulnerability is a race condition in the max17040_suspend() function in drivers/power/supply/max17040_battery.c. The function uses cancel_delayed_work() which only cancels a pending work item but does not wait for a callback already in execution. If system suspend races with the max17040_work() polling callback, the callback can continue accessing the fuel gauge and requeue itself after suspend returns. The fix replaces cancel_delayed_work() with cancel_delayed_work_sync() to synchronously cancel and wait for the work item to complete before suspend finishes. This affects all kernel versions since the MAX17040 driver was introduced (commit c6f4a42de60b).
Affected products
- Linux Linux kernel All versions containing the MAX17040 fuel gauge driver (since c6f4a42de60b)
Timeline
- 2026-09-11: disclosed: Published to NVD
- 2026-08-10: patched: Fix committed upstream by Jianing Li
- 2026-09-07: patched: Backported to stable kernels