In the Linux kernel, the following vulnerability has been resolved:
power: supply: max17040: synchronize work cancellation on suspend
max17040_work() requeues itself after every poll. cancel_delayed_work()
only cancels a pending instance and does not wait for a callback that is
already running.
If system suspend races with the polling callback, the callback can
continue accessing the fuel gauge and requeue itself after the suspend
callback returns.
Use cancel_delayed_work_sync() to ensure polling is quiesced before
suspend completes.
CVE-2026-89461
NONE
EPSS 0.21%
Updated Sep 14, 2026
Linux
https://git.kernel.org/stable/c/36e6ce0f402f965328b27fd31ac793110e8a0c39
416baaa9-dc9f-4396-8d5f-8c081fb06d67
https://git.kernel.org/stable/c/5a863417fb9a1034ab1cfe4fa0de46ce1f95f3ec
416baaa9-dc9f-4396-8d5f-8c081fb06d67
https://git.kernel.org/stable/c/86a3a8a926aa5969c329d1df2d3259f189961bbc
416baaa9-dc9f-4396-8d5f-8c081fb06d67
https://git.kernel.org/stable/c/aad7247bd35ad44af90a5e8974cdff614235b497
416baaa9-dc9f-4396-8d5f-8c081fb06d67
https://git.kernel.org/stable/c/23783db5642a714f0547c5b5b0c9cdbb1be7b084
416baaa9-dc9f-4396-8d5f-8c081fb06d67
https://git.kernel.org/stable/c/6bd453e328a0325f838c3bf64d4609c6c1866ed7
416baaa9-dc9f-4396-8d5f-8c081fb06d67
https://git.kernel.org/stable/c/7a9ec6707b545b2a0b35942c8b68d975cb901f77
416baaa9-dc9f-4396-8d5f-8c081fb06d67
https://git.kernel.org/stable/c/dc946222e4b5bdb4e92bc3a5a5e8fc4ddac34ec0
416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVE Details
CVE ID
CVE-2026-89461
Published Date
Sep 11, 2026
Vendor
Linux
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.21%
Likelihood of exploitation in next 30 days
Percentile:
10.3th percentile (higher than 10.3% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory