« Volver al listado

CVE-2026-98000

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

hwmon: Fix potential UAF in pec_store

Sashiko reports:

In pec_store(), a guard(mutex)(&hwdev->lock) is taken. If the chip write operation returns an error other than -EOPNOTSUPP, the code jumps to the put label, which calls put_device(hdev). If this drops the final reference, the device is freed. When the function then returns, the guard cleanup function runs and attempts to unlock the freed mutex.

Use scoped_guard() instead of guard() to avoid the problem.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98000",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3ad2a7b9b15d5072139a20be84adb36776eb6c9b",
              "lessThan": "8afab57bcdbc2186f325972e777880ac5a220f4f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3ad2a7b9b15d5072139a20be84adb36776eb6c9b",
              "lessThan": "01dd8b4fc2cf83c66565c0f382fb1841e9000a89",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3ad2a7b9b15d5072139a20be84adb36776eb6c9b",
              "lessThan": "354ccc99b2dc8ba0cf6d4de34e520bcf6ecca5c2",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/hwmon/hwmon.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.18"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.18",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc3",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/hwmon/hwmon.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:28.213",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/01dd8b4fc2cf83c66565c0f382fb1841e9000a89",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/354ccc99b2dc8ba0cf6d4de34e520bcf6ecca5c2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8afab57bcdbc2186f325972e777880ac5a220f4f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: Fix potential UAF in pec_store\n\nSashiko reports:\n\nIn pec_store(), a guard(mutex)(&hwdev->lock) is taken. If the chip write\noperation returns an error other than -EOPNOTSUPP, the code jumps to the\nput label, which calls put_device(hdev). If this drops the final reference,\nthe device is freed. When the function then returns, the guard cleanup\nfunction runs and attempts to unlock the freed mutex.\n\nUse scoped_guard() instead of guard() to avoid the problem."
    }
  ],
  "lastModified": "2026-09-25T11:17:28.213",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}