PT-2026-98522 · Linux · Linux Kernel

CVE-2026-97582

·

Published

2026-09-25

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A use-after-free issue exists in the gpio-fan driver of the hwmon subsystem. The fan alarm irq handler() function queues fan data->alarm work, but the system fails to cancel this work during the unbind process. Consequently, the fan alarm notify() function may attempt to dereference fan data and its associated hwmon device after they have been released by devres, leading to a potential crash or memory corruption.
Recommendations Replace the INIT WORK() function with devm work autocancel(), ensuring it is registered before devm request irq() to ensure work is cancelled before the device and data are freed.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-97582

Affected Products

Linux Kernel