Impact
The Linux kernel power supply driver for the max17040 battery gauge does not propagate I2C register read errors raised by regmap_read(). When a transfer fails, the driver interprets the uninitialized register value as a valid measurement, reporting incorrect voltage or state‑of‑charge to user space. This flaw is a CWE‑908 vulnerability where error values are treated as legitimate data, leading to misleading telemetry. While there is no privilege escalation or code execution path, the incorrect battery information can mislead power management decisions and trigger false alerts.
Affected Systems
All Linux kernel installations that load the max17040 battery gauge driver are affected. The issue exists in any kernel version containing the unpatched driver code; specific kernel releases are not enumerated in the CVE data.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS is reported as <1%, showing a very low exploitation probability. The vulnerability is not listed in CISA KEV, and the likely attack vector requires local access to the I2C bus to induce a communication failure. Exploitation would produce erroneous battery readings and potential false power‑management events, causing reliability or availability problems but not immediate critical impact.
OpenCVE Enrichment
Debian DSA