-

CVE-2026-98000

hwmon: Fix potential UAF in pec_store

In the Linux kernel, the following vulnerability has been resolved:

hwmon: Fix potential UAF in pec_store

Sashiko reports:

In pec_store(), a guard(mutex)(&hwdev->lock) is taken. If the chip write
operation returns an error other than -EOPNOTSUPP, the code jumps to the
put label, which calls put_device(hdev). If this drops the final reference,
the device is freed. When the function then returns, the guard cleanup
function runs and attempts to unlock the freed mutex.

Use scoped_guard() instead of guard() to avoid the problem.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 3ad2a7b9b15d5072139a20be84adb36776eb6c9b
Version < 8afab57bcdbc2186f325972e777880ac5a220f4f
Status affected
Version 3ad2a7b9b15d5072139a20be84adb36776eb6c9b
Version < 01dd8b4fc2cf83c66565c0f382fb1841e9000a89
Status affected
Version 3ad2a7b9b15d5072139a20be84adb36776eb6c9b
Version < 354ccc99b2dc8ba0cf6d4de34e520bcf6ecca5c2
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.18
Status affected
Version 0
Version < 6.18
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc3
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.052
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/8afab57bcdbc2186f325972e777880ac5a220f4f
https://git.kernel.org/stable/c/01dd8b4fc2cf83c66565c0f382fb1841e9000a89
https://git.kernel.org/stable/c/354ccc99b2dc8ba0cf6d4de34e520bcf6ecca5c2