-

CVE-2026-98200

hwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show()

In the Linux kernel, the following vulnerability has been resolved:

hwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show()

nsensor->current_state is dynamically replaced as the sensor's state
changes. update_numeric_sensor_from_wobj() does this by freeing the
old string and installing a new one:

	if (strcmp(trimmed, nsensor->current_state)) {
		new_string = hp_wmi_strdup(dev, trimmed);
		if (new_string) {
			devm_kfree(dev, nsensor->current_state);
			nsensor->current_state = new_string;
		}
	}

This function is only ever called from hp_wmi_update_info() while
state->lock is held, so the free-and-replace itself is properly
serialized against concurrent updates.

fungible_show(), however, reads the same pointer after the lock has
already been dropped:

	err = hp_wmi_update_info(state, info);
	if (err)
		return err;

	switch (prop) {
	...
	case HP_WMI_PROPERTY_CURRENT_STATE:
		seq_printf(seqf, "%s\n", nsensor->current_state);
		break;

hp_wmi_update_info() takes state->lock internally and releases it
before returning, so by the time fungible_show() dereferences
nsensor->current_state in seq_printf(), no lock is held. Two
processes reading a sensor's current_state debugfs entry at
overlapping times (or one reading it while another read of the same
sensor triggers a refresh) can race: one thread's seq_printf() can
be part-way through printing the string at the moment another
thread's call into update_numeric_sensor_from_wobj() frees it with
devm_kfree() and installs a new pointer, causing a use-after-free
read.

Take state->lock around the read in fungible_show() as well, so it
can never run concurrently with the free-and-replace in
update_numeric_sensor_from_wobj().
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 23902f98f8d4811ab84dde6419569a5b374f8122
Version < b6b2a638aa36c441b2c8d0b6bd8ed2bb9701e795
Status affected
Version 23902f98f8d4811ab84dde6419569a5b374f8122
Version < f59ecfd2c58bace39538f3fff7f43788b3fdb539
Status affected
Version 23902f98f8d4811ab84dde6419569a5b374f8122
Version < 72c85149794a1ccf8d718ffed1521106b5d31968
Status affected
Version 23902f98f8d4811ab84dde6419569a5b374f8122
Version < 9c1e65bc79ff104914b11e6ad972139296ec86fe
Status affected
Version 23902f98f8d4811ab84dde6419569a5b374f8122
Version < e6cb0b4d4ecb8e71fd2200d907ab2e9663356f69
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.5
Status affected
Version 0
Version < 6.5
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.54
Status unaffected
Version <= 7.2.*
Version 7.2.8
Status unaffected
Version <= *
Version 7.3-rc4
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.064
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/b6b2a638aa36c441b2c8d0b6bd8ed2bb9701e795
https://git.kernel.org/stable/c/f59ecfd2c58bace39538f3fff7f43788b3fdb539
https://git.kernel.org/stable/c/72c85149794a1ccf8d718ffed1521106b5d31968
https://git.kernel.org/stable/c/9c1e65bc79ff104914b11e6ad972139296ec86fe
https://git.kernel.org/stable/c/e6cb0b4d4ecb8e71fd2200d907ab2e9663356f69