CVE-2026-93142
In the Linux kernel, the following vulnerability has been resolved:
thermal/drivers/rcar: Fix error checking in probe()
This code accidentally calls thermal_zone_device_enable() before checking whether thermal_zone_device_register_with_trips() failed. Move the call until later to avoid an error pointer dereference of "priv->zone".
The driver works differently depending on if we are using OF thermal or not. We use thermal_add_hwmon_sysfs() if we are using OF thermal and call thermal_zone_device_enable() if not. We can share same error check for if either of these fail.
Moving the thermal_zone_device_enable() call is a bit cleaner as well. The original code used a three step process to cleanup: 1. Call thermal_zone_device_unregister() to cleanup. 2.
Leer descripción completaMostrar menos
Set priv->zone to an error pointer to preserve the error code. 3. Set priv->zone to NULL to avoid a second call to thermal_zone_device_unregister() in the rcar_thermal_remove() function.
Now we can just do a direct goto error_unregister and rcar_thermal_remove() handles the cleanup properly.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 11
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/35bf61798e7d4abf39667d98f298f793b3dd9bbe
- https://git.kernel.org/stable/c/623349a18d4c6e6add7876553c0cb6947c8d92e6
- https://git.kernel.org/stable/c/810875c5996f731961fc5ee1bd24e711f2e8fe78
- https://git.kernel.org/stable/c/a85bcd0c7ef66e3404b3c99e5589c5ea622a757e
- https://git.kernel.org/stable/c/d67607e7749527850619a10d3ed033b02dcea516
- https://git.kernel.org/stable/c/dd04ad1cdabcad51e34b74b4e91b9aeb7180d05d
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-93142",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "bbcf90c0646ac797700269fa6645a6a46466c79f",
"lessThan": "a85bcd0c7ef66e3404b3c99e5589c5ea622a757e",
"versionType": "git"
},
{
"status": "affected",
"version": "bbcf90c0646ac797700269fa6645a6a46466c79f",
"lessThan": "810875c5996f731961fc5ee1bd24e711f2e8fe78",
"versionType": "git"
},
{
"status": "affected",
"version": "bbcf90c0646ac797700269fa6645a6a46466c79f",
"lessThan": "623349a18d4c6e6add7876553c0cb6947c8d92e6",
"versionType": "git"
},
{
"status": "affected",
"version": "bbcf90c0646ac797700269fa6645a6a46466c79f",
"lessThan": "35bf61798e7d4abf39667d98f298f793b3dd9bbe",
"versionType": "git"
},
{
"status": "affected",
"version": "bbcf90c0646ac797700269fa6645a6a46466c79f",
"lessThan": "d67607e7749527850619a10d3ed033b02dcea516",
"versionType": "git"
},
{
"status": "affected",
"version": "bbcf90c0646ac797700269fa6645a6a46466c79f",
"lessThan": "dd04ad1cdabcad51e34b74b4e91b9aeb7180d05d",
"versionType": "git"
}
],
"programFiles": [
"drivers/thermal/renesas/rcar_thermal.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.9"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.9",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.1.188",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.157",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.110",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.52",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.6",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/thermal/renesas/rcar_thermal.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-17T17:18:09.267",
"references": [
{
"url": "https://git.kernel.org/stable/c/35bf61798e7d4abf39667d98f298f793b3dd9bbe",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/623349a18d4c6e6add7876553c0cb6947c8d92e6",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/810875c5996f731961fc5ee1bd24e711f2e8fe78",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a85bcd0c7ef66e3404b3c99e5589c5ea622a757e",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d67607e7749527850619a10d3ed033b02dcea516",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/dd04ad1cdabcad51e34b74b4e91b9aeb7180d05d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nthermal/drivers/rcar: Fix error checking in probe()\n\nThis code accidentally calls thermal_zone_device_enable() before checking\nwhether thermal_zone_device_register_with_trips() failed. Move the call\nuntil later to avoid an error pointer dereference of \"priv->zone\".\n\nThe driver works differently depending on if we are using OF thermal or\nnot. We use thermal_add_hwmon_sysfs() if we are using OF thermal and\ncall thermal_zone_device_enable() if not. We can share same error check\nfor if either of these fail.\n\nMoving the thermal_zone_device_enable() call is a bit cleaner as well.\nThe original code used a three step process to cleanup:\n1. Call thermal_zone_device_unregister() to cleanup.\n2. Set priv->zone to an error pointer to preserve the error code.\n3. Set priv->zone to NULL to avoid a second call to\n thermal_zone_device_unregister() in the rcar_thermal_remove()\n function.\n\nNow we can just do a direct goto error_unregister and rcar_thermal_remove()\nhandles the cleanup properly."
}
],
"lastModified": "2026-09-17T17:18:09.267",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}