CVE-2026-98197
In the Linux kernel, the following vulnerability has been resolved:
hwmon: (w83791d) remove fan/pwm 4-5 sysfs group on remove
When the fan/pwm 4-5 pins are not used as GPIO, w83791d_probe() creates the w83791d_group_fanpwm45 sysfs group on the I2C client device.
The probe error path removes this group when a later initialization step fails, but the normal remove path only removes w83791d_group. As a result, the optional fan/pwm 4-5 sysfs files can remain after the driver is unbound.
The callbacks associated with these files access the driver data, which is devm allocated and released after driver unbind. Leaving the sysfs files behind can therefore result in accesses to stale driver data.
Leer descripción completaMostrar menos
Remove w83791d_group_fanpwm45 during normal teardown as well.
This issue was found by manual code inspection.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.22%
- Percentil entre todas las CVEs puntuadas: 11
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/081e3a78453635fb370b1712809d2af29e60b4c5
- https://git.kernel.org/stable/c/0ff9c7775e51ac6d47b1bb5c46f06b1434fe58a8
- https://git.kernel.org/stable/c/2c381e6e0f033f2df13bd64905e7232c42f49009
- https://git.kernel.org/stable/c/2ccf6c512290a288a2d4d7f076430dfb0c6ee476
- https://git.kernel.org/stable/c/2dd37d00f1f1af8e02ffa70ee573c10fd1a76864
- https://git.kernel.org/stable/c/583e04e88e75b8d57304015d83c38e82a9531600
- https://git.kernel.org/stable/c/b1d419eb3bc41245c3d3d99dfe1a7b6c45989586
- https://git.kernel.org/stable/c/f6e2ab72f32d16d71a2549c7ea062dd209f71670
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-98197",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6e1ecd9b8f1358ed4d099f0c54434240dc40debe",
"lessThan": "081e3a78453635fb370b1712809d2af29e60b4c5",
"versionType": "git"
},
{
"status": "affected",
"version": "6e1ecd9b8f1358ed4d099f0c54434240dc40debe",
"lessThan": "b1d419eb3bc41245c3d3d99dfe1a7b6c45989586",
"versionType": "git"
},
{
"status": "affected",
"version": "6e1ecd9b8f1358ed4d099f0c54434240dc40debe",
"lessThan": "2ccf6c512290a288a2d4d7f076430dfb0c6ee476",
"versionType": "git"
},
{
"status": "affected",
"version": "6e1ecd9b8f1358ed4d099f0c54434240dc40debe",
"lessThan": "f6e2ab72f32d16d71a2549c7ea062dd209f71670",
"versionType": "git"
},
{
"status": "affected",
"version": "6e1ecd9b8f1358ed4d099f0c54434240dc40debe",
"lessThan": "2dd37d00f1f1af8e02ffa70ee573c10fd1a76864",
"versionType": "git"
},
{
"status": "affected",
"version": "6e1ecd9b8f1358ed4d099f0c54434240dc40debe",
"lessThan": "2c381e6e0f033f2df13bd64905e7232c42f49009",
"versionType": "git"
},
{
"status": "affected",
"version": "6e1ecd9b8f1358ed4d099f0c54434240dc40debe",
"lessThan": "583e04e88e75b8d57304015d83c38e82a9531600",
"versionType": "git"
},
{
"status": "affected",
"version": "6e1ecd9b8f1358ed4d099f0c54434240dc40debe",
"lessThan": "0ff9c7775e51ac6d47b1bb5c46f06b1434fe58a8",
"versionType": "git"
}
],
"programFiles": [
"drivers/hwmon/w83791d.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.28"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "2.6.28",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.271",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.222",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.189",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.158",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.112",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.54",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.8",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc4",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/hwmon/w83791d.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-10-06T09:18:05.273",
"references": [
{
"url": "https://git.kernel.org/stable/c/081e3a78453635fb370b1712809d2af29e60b4c5",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/0ff9c7775e51ac6d47b1bb5c46f06b1434fe58a8",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/2c381e6e0f033f2df13bd64905e7232c42f49009",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/2ccf6c512290a288a2d4d7f076430dfb0c6ee476",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/2dd37d00f1f1af8e02ffa70ee573c10fd1a76864",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/583e04e88e75b8d57304015d83c38e82a9531600",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/b1d419eb3bc41245c3d3d99dfe1a7b6c45989586",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f6e2ab72f32d16d71a2549c7ea062dd209f71670",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (w83791d) remove fan/pwm 4-5 sysfs group on remove\n\nWhen the fan/pwm 4-5 pins are not used as GPIO, w83791d_probe()\ncreates the w83791d_group_fanpwm45 sysfs group on the I2C client\ndevice.\n\nThe probe error path removes this group when a later initialization\nstep fails, but the normal remove path only removes w83791d_group.\nAs a result, the optional fan/pwm 4-5 sysfs files can remain after the\ndriver is unbound.\n\nThe callbacks associated with these files access the driver data,\nwhich is devm allocated and released after driver unbind. Leaving the\nsysfs files behind can therefore result in accesses to stale driver\ndata.\n\nRemove w83791d_group_fanpwm45 during normal teardown as well.\n\nThis issue was found by manual code inspection."
}
],
"lastModified": "2026-10-06T09:18:05.273",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}