PT-2026-98522 · Linux · Linux Kernel
CVE-2026-97582
·
Published
2026-09-25
·
Updated
2026-09-25
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A use-after-free issue exists in the
gpio-fan driver of the hwmon subsystem. The fan alarm irq handler() function queues fan data->alarm work, but the system fails to cancel this work during the unbind process. Consequently, the fan alarm notify() function may attempt to dereference fan data and its associated hwmon device after they have been released by devres, leading to a potential crash or memory corruption.Recommendations
Replace the
INIT WORK() function with devm work autocancel(), ensuring it is registered before devm request irq() to ensure work is cancelled before the device and data are freed. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel