{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  power: supply: max17040: propagate register read errors  max17040_get_vcell() and max17040_get_soc() ignore errors returned by regmap_read().  When an I2C transfer fails, the uninitialized register value is converted and reported to userspace as a valid voltage or state of charge.  The polling worker can also replace the cached state of charge with the bogus value and emit a spurious change event.  Propagate read errors through the power supply get_property callback and keep the last valid cached state of charge when polling fails.",
  "id": "DEBIAN-CVE-2026-89462",
  "modified": "2026-09-12T08:47:19.720725544Z",
  "published": "2026-09-11T20:19:27.157Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-89462"
    }
  ],
  "upstream": [
    "CVE-2026-89462"
  ]
}