CVE-2026-64038
In the Linux kernel, the following vulnerability has been resolved:
hwmon: (lm90) Stop work before releasing hwmon device
Sashiko reports:
In lm90_probe(), the devm action to cancel the alert_work and report_work (lm90_restore_conf) is registered in lm90_init_client() before devm_hwmon_device_register_with_info() is called.
Because devm executes cleanup actions in reverse order during module unbind or probe failure, the hwmon device is unregistered and freed first.
If lm90_alert_work() or lm90_report_alarms() runs in the window between the hwmon device being freed and the delayed works being cancelled, lm90_update_alarms() will dereference the freed data->hwmon_dev here.
Leer descripción completaMostrar menos
Fix the problem by canceling the workers separately after registering the hwmon device and before registering the interrupt handler. This ensures that the workers are canceled after interrupts are disabled and before the hwmon device is released. Add "shutdown" flag to indicate that device shutdown is in progress to prevent workers from being re-armed.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-64038",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "f6d0775119fb905fb02eafa98d575cf8ee792d46",
"lessThan": "c98107817b0f6cdf51adc5e84e75c39ee25d8b28",
"versionType": "git"
},
{
"status": "affected",
"version": "f6d0775119fb905fb02eafa98d575cf8ee792d46",
"lessThan": "479e297526aeb19c745eac5c1897f455f83dc5f8",
"versionType": "git"
},
{
"status": "affected",
"version": "f6d0775119fb905fb02eafa98d575cf8ee792d46",
"lessThan": "b09a45601094c7f4ec4db8090b825fa61e169d93",
"versionType": "git"
}
],
"programFiles": [
"drivers/hwmon/lm90.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.0"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver",
"lessThanOrEqual": "7.0.*"
},
{
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/hwmon/lm90.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-07-19T16:17:44.053",
"references": [
{
"url": "https://git.kernel.org/stable/c/479e297526aeb19c745eac5c1897f455f83dc5f8",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/b09a45601094c7f4ec4db8090b825fa61e169d93",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c98107817b0f6cdf51adc5e84e75c39ee25d8b28",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Awaiting Analysis",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (lm90) Stop work before releasing hwmon device\n\nSashiko reports:\n\nIn lm90_probe(), the devm action to cancel the alert_work and report_work\n(lm90_restore_conf) is registered in lm90_init_client() before\ndevm_hwmon_device_register_with_info() is called.\n\nBecause devm executes cleanup actions in reverse order during module\nunbind or probe failure, the hwmon device is unregistered and freed first.\n\nIf lm90_alert_work() or lm90_report_alarms() runs in the window between\nthe hwmon device being freed and the delayed works being cancelled,\nlm90_update_alarms() will dereference the freed data->hwmon_dev here.\n\nFix the problem by canceling the workers separately after registering\nthe hwmon device and before registering the interrupt handler. This ensures\nthat the workers are canceled after interrupts are disabled and before\nthe hwmon device is released. Add \"shutdown\" flag to indicate that device\nshutdown is in progress to prevent workers from being re-armed."
}
],
"lastModified": "2026-07-30T14:59:47.950",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}