CVE-2026-45914
In the Linux kernel, the following vulnerability has been resolved:
Revert "hwmon: (ibmpex) fix use-after-free in high/low store"
This reverts commit 6946c726c3f4c36f0f049e6f97e88c510b15f65d.
Jean Delvare points out that the patch does not completely fix the reported problem, that it in fact introduces a (new) race condition, and that it may actually not be needed in the first place.
Various AI reviews agree. Specific and relevant AI feedback:
" This reordering sets the driver data to NULL before removing the sensor attributes in the loop below.
ibmpex_show_sensor() retrieves this driver data via dev_get_drvdata() but does not check if it is NULL before dereferencing it to access data->sensors[].
Leer descripción completaMostrar menos
If a userspace process reads a sensor file (like temp1_input) while this delete function is running, could it race with the dev_set_drvdata(..., NULL) call here and crash in ibmpex_show_sensor()?
Would it be safer to keep the original order where device_remove_file() is called before clearing the driver data? device_remove_file() should wait for any active sysfs callbacks to complete, which might already prevent the use-after-free this patch intends to fix. "
Revert the offending patch. If it can be shown that the originally reported alleged race condition does indeed exist, it can always be re-introduced with a complete fix.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.17%
- Percentil entre todas las CVEs puntuadas: 6
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation85 % - Impacto principal
T1059Command and Scripting Interpreterexecution75 %
Vulnerabilidad de use-after-free (CWE-416) en driver hwmon de Linux con acceso local y privilegios (AV:L, PR:L). Permite dereferenciación NULL y ejecución de código arbitrario tras escalada de privilegios local.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-416
Referencias
- https://git.kernel.org/stable/c/05112ba67c824ab416cd54307c0b50aba9f0047a
- https://git.kernel.org/stable/c/14a38784e09aebc21207dc32fffa05247fc3dd64
- https://git.kernel.org/stable/c/894d9c7aab68fd0c70c78b1d03c8fa589fb0f67d
- https://git.kernel.org/stable/c/8bde3e395a85017f12af2b0ba5c3684f5af9c006
- https://git.kernel.org/stable/c/914b47c9b824d3d74f31c764163edf93302100b1
- https://git.kernel.org/stable/c/efd68429f23fb4015b0ebc2392334059e06fad18
- https://git.kernel.org/stable/c/f448acd86835a650f9ea83460b9ca347d3aafba5
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-45914",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "3ce9b7ae9d4d148672b35147aaf7987a4f82bb94",
"lessThan": "05112ba67c824ab416cd54307c0b50aba9f0047a",
"versionType": "git"
},
{
"status": "affected",
"version": "533ead425f8109b02fecc7e72d612b8898ec347a",
"lessThan": "efd68429f23fb4015b0ebc2392334059e06fad18",
"versionType": "git"
},
{
"status": "affected",
"version": "fa37adcf1d564ef58b9dfb01b6c36d35c5294bad",
"lessThan": "f448acd86835a650f9ea83460b9ca347d3aafba5",
"versionType": "git"
},
{
"status": "affected",
"version": "68d62e5bebbd118b763e8bb210d5cf2198ef450c",
"lessThan": "914b47c9b824d3d74f31c764163edf93302100b1",
"versionType": "git"
},
{
"status": "affected",
"version": "5aa2139201667c1f644601e4529c4acd6bf8db5a",
"lessThan": "14a38784e09aebc21207dc32fffa05247fc3dd64",
"versionType": "git"
},
{
"status": "affected",
"version": "6946c726c3f4c36f0f049e6f97e88c510b15f65d",
"lessThan": "894d9c7aab68fd0c70c78b1d03c8fa589fb0f67d",
"versionType": "git"
},
{
"status": "affected",
"version": "6946c726c3f4c36f0f049e6f97e88c510b15f65d",
"lessThan": "8bde3e395a85017f12af2b0ba5c3684f5af9c006",
"versionType": "git"
},
{
"status": "affected",
"version": "5.10.248",
"lessThan": "5.10.252",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.1.160",
"lessThan": "6.1.165",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.6.120",
"lessThan": "6.6.128",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.12.64",
"lessThan": "6.12.75",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.18.3",
"lessThan": "6.18.14",
"versionType": "semver"
}
],
"programFiles": [
"drivers/hwmon/ibmpex.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.19"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.19",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.252",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "6.1.165",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.128",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.75",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.14",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "6.19.4",
"versionType": "semver",
"lessThanOrEqual": "6.19.*"
},
{
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/hwmon/ibmpex.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-05-27T14:17:06.180",
"references": [
{
"url": "https://git.kernel.org/stable/c/05112ba67c824ab416cd54307c0b50aba9f0047a",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/14a38784e09aebc21207dc32fffa05247fc3dd64",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/894d9c7aab68fd0c70c78b1d03c8fa589fb0f67d",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/8bde3e395a85017f12af2b0ba5c3684f5af9c006",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/914b47c9b824d3d74f31c764163edf93302100b1",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/efd68429f23fb4015b0ebc2392334059e06fad18",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f448acd86835a650f9ea83460b9ca347d3aafba5",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Undergoing Analysis",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-416"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRevert \"hwmon: (ibmpex) fix use-after-free in high/low store\"\n\nThis reverts commit 6946c726c3f4c36f0f049e6f97e88c510b15f65d.\n\nJean Delvare points out that the patch does not completely\nfix the reported problem, that it in fact introduces a\n(new) race condition, and that it may actually not be needed in\nthe first place.\n\nVarious AI reviews agree. Specific and relevant AI feedback:\n\n\"\nThis reordering sets the driver data to NULL before removing the sensor\nattributes in the loop below.\n\nibmpex_show_sensor() retrieves this driver data via dev_get_drvdata() but\ndoes not check if it is NULL before dereferencing it to access\ndata->sensors[].\n\nIf a userspace process reads a sensor file (like temp1_input) while this\ndelete function is running, could it race with the dev_set_drvdata(...,\nNULL) call here and crash in ibmpex_show_sensor()?\n\nWould it be safer to keep the original order where device_remove_file() is\ncalled before clearing the driver data? device_remove_file() should wait\nfor any active sysfs callbacks to complete, which might already prevent the\nuse-after-free this patch intends to fix.\n\"\n\nRevert the offending patch. If it can be shown that the originally reported\nalleged race condition does indeed exist, it can always be re-introduced\nwith a complete fix."
}
],
"lastModified": "2026-06-24T14:55:01.837",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0FF383F2-E238-49E9-870A-004DCE6EC4EE",
"versionEndExcluding": "5.10.252",
"versionStartIncluding": "5.10.248"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "29CE5815-AC25-4B86-8093-9B7C33747C6A",
"versionEndExcluding": "6.1.165",
"versionStartIncluding": "6.1.160"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F93EE437-1C07-464F-9047-8987F00BA711",
"versionEndExcluding": "6.6.128",
"versionStartIncluding": "6.6.120"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E27D5D92-2E0F-4CED-BEFE-15984B8B010D",
"versionEndExcluding": "6.12.75",
"versionStartIncluding": "6.12.64"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1F86B087-7282-4A5E-92B3-E7448F7492B3",
"versionEndExcluding": "6.18.14",
"versionStartIncluding": "6.18.3"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "411B9362-5B74-4569-8450-50CAD50DE99C",
"versionEndExcluding": "6.19.4",
"versionStartIncluding": "6.19.1"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.19:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "35C8A871-4971-433E-A046-FC9F7B7D190A"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.19:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C47E4CC9-C826-4FA9-B014-7FE3D9B318B2"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.19:rc3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F71D92C0-C023-48BD-B3B6-70B638EEE298"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.19:rc4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "13580667-0A98-40CC-B29F-D12790B91BDB"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.19:rc5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CAD1FED7-CF48-47BF-AC7D-7B6FA3C065FC"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.19:rc6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3EF854A1-ABB1-4E93-BE9A-44569EC76C0D"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.19:rc7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F5DC0CA6-F0AF-4DDF-A882-3DADB9A886A7"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.19:rc8:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EB5B7DFC-C36B-45D8-922C-877569FDDF43"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}