PT-2026-106529 · Linux · Linux

CVE-2026-98200

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
hwmon: (hp-wmi-sensors) Fix use-after-free in fungible show()
nsensor->current state is dynamically replaced as the sensor's state changes. update numeric sensor from wobj() does this by freeing the old string and installing a new one:
if (strcmp(trimmed, nsensor->current state)) {
	new string = hp wmi strdup(dev, trimmed);
	if (new string) {
		devm kfree(dev, nsensor->current state);
		nsensor->current state = new string;
	}
}
This function is only ever called from hp wmi update info() while state->lock is held, so the free-and-replace itself is properly serialized against concurrent updates.
fungible show(), however, reads the same pointer after the lock has already been dropped:
err = hp wmi update info(state, info);
if (err)
	return err;

switch (prop) {
...
case HP WMI PROPERTY CURRENT STATE:
	seq printf(seqf, "%s
", nsensor->current state); break;
hp wmi update info() takes state->lock internally and releases it before returning, so by the time fungible show() dereferences nsensor->current state in seq printf(), no lock is held. Two processes reading a sensor's current state debugfs entry at overlapping times (or one reading it while another read of the same sensor triggers a refresh) can race: one thread's seq printf() can be part-way through printing the string at the moment another thread's call into update numeric sensor from wobj() frees it with devm kfree() and installs a new pointer, causing a use-after-free read.
Take state->lock around the read in fungible show() as well, so it can never run concurrently with the free-and-replace in update numeric sensor from wobj().
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98200

Affected Products

Linux