« Volver al listado

CVE-2026-98200

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

hwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show()

nsensor->current_state is dynamically replaced as the sensor's state changes. update_numeric_sensor_from_wobj() does this by freeing the old string and installing a new one:

This function is only ever called from hp_wmi_update_info() while state->lock is held, so the free-and-replace itself is properly serialized against concurrent updates.

fungible_show(), however, reads the same pointer after the lock has already been dropped:

hp_wmi_update_info() takes state->lock internally and releases it before returning, so by the time fungible_show() dereferences nsensor->current_state in seq_printf(), no lock is held.

Leer descripción completaMostrar menos

Two processes reading a sensor's current_state debugfs entry at overlapping times (or one reading it while another read of the same sensor triggers a refresh) can race: one thread's seq_printf() can be part-way through printing the string at the moment another thread's call into update_numeric_sensor_from_wobj() frees it with devm_kfree() and installs a new pointer, causing a use-after-free read.

Take state->lock around the read in fungible_show() as well, so it can never run concurrently with the free-and-replace in update_numeric_sensor_from_wobj().

Detalles técnicos trazas, registros y código del informe original
	if (strcmp(trimmed, nsensor->current_state)) {
		new_string = hp_wmi_strdup(dev, trimmed);
		if (new_string) {
			devm_kfree(dev, nsensor->current_state);
			nsensor->current_state = new_string;
		}
	}

	err = hp_wmi_update_info(state, info);
	if (err)
		return err;

	switch (prop) {
	...
	case HP_WMI_PROPERTY_CURRENT_STATE:
		seq_printf(seqf, "%s\n", nsensor->current_state);
		break;

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98200",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "23902f98f8d4811ab84dde6419569a5b374f8122",
              "lessThan": "b6b2a638aa36c441b2c8d0b6bd8ed2bb9701e795",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "23902f98f8d4811ab84dde6419569a5b374f8122",
              "lessThan": "f59ecfd2c58bace39538f3fff7f43788b3fdb539",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "23902f98f8d4811ab84dde6419569a5b374f8122",
              "lessThan": "72c85149794a1ccf8d718ffed1521106b5d31968",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "23902f98f8d4811ab84dde6419569a5b374f8122",
              "lessThan": "9c1e65bc79ff104914b11e6ad972139296ec86fe",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "23902f98f8d4811ab84dde6419569a5b374f8122",
              "lessThan": "e6cb0b4d4ecb8e71fd2200d907ab2e9663356f69",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/hwmon/hp-wmi-sensors.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.5"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.5",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/hwmon/hp-wmi-sensors.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-10-06T09:18:05.747",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/72c85149794a1ccf8d718ffed1521106b5d31968",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9c1e65bc79ff104914b11e6ad972139296ec86fe",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b6b2a638aa36c441b2c8d0b6bd8ed2bb9701e795",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e6cb0b4d4ecb8e71fd2200d907ab2e9663356f69",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f59ecfd2c58bace39538f3fff7f43788b3fdb539",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show()\n\nnsensor->current_state is dynamically replaced as the sensor's state\nchanges. update_numeric_sensor_from_wobj() does this by freeing the\nold string and installing a new one:\n\n\tif (strcmp(trimmed, nsensor->current_state)) {\n\t\tnew_string = hp_wmi_strdup(dev, trimmed);\n\t\tif (new_string) {\n\t\t\tdevm_kfree(dev, nsensor->current_state);\n\t\t\tnsensor->current_state = new_string;\n\t\t}\n\t}\n\nThis function is only ever called from hp_wmi_update_info() while\nstate->lock is held, so the free-and-replace itself is properly\nserialized against concurrent updates.\n\nfungible_show(), however, reads the same pointer after the lock has\nalready been dropped:\n\n\terr = hp_wmi_update_info(state, info);\n\tif (err)\n\t\treturn err;\n\n\tswitch (prop) {\n\t...\n\tcase HP_WMI_PROPERTY_CURRENT_STATE:\n\t\tseq_printf(seqf, \"%s\\n\", nsensor->current_state);\n\t\tbreak;\n\nhp_wmi_update_info() takes state->lock internally and releases it\nbefore returning, so by the time fungible_show() dereferences\nnsensor->current_state in seq_printf(), no lock is held. Two\nprocesses reading a sensor's current_state debugfs entry at\noverlapping times (or one reading it while another read of the same\nsensor triggers a refresh) can race: one thread's seq_printf() can\nbe part-way through printing the string at the moment another\nthread's call into update_numeric_sensor_from_wobj() frees it with\ndevm_kfree() and installs a new pointer, causing a use-after-free\nread.\n\nTake state->lock around the read in fungible_show() as well, so it\ncan never run concurrently with the free-and-replace in\nupdate_numeric_sensor_from_wobj()."
    }
  ],
  "lastModified": "2026-10-06T09:18:05.747",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}