CVE-2026-74552 PUBLISHED

hwmon: (lm90) Only report alarms if driver is ready

Assigner: Linux
Reserved: 15.08.2026 Published: 15.08.2026 Updated: 15.08.2026

In the Linux kernel, the following vulnerability has been resolved:

hwmon: (lm90) Only report alarms if driver is ready

Userspace can read sysfs attributes before driver registration is complete, immediately after devm_hwmon_device_register_with_info() has been called. At that time, data->hwmon_dev is not yet initialized. This can trigger a NULL pointer access since lm90_update_device() and with it lm90_update_alarms_locked() will be called. This call schedules report_work and lm90_report_alarms(), which passes the still-NULL data->hwmon_dev to hwmon_notify_event() and triggers a NULL pointer dereference.

Fix the problem by only scheduling the report and alert workers data->hwmon_dev is set.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from f6d0775119fb905fb02eafa98d575cf8ee792d46 to 4eed33c7db5c0c573928d28d8a2c003642c679b8 (excl.)
  • affected from f6d0775119fb905fb02eafa98d575cf8ee792d46 to 70d9a71aa407044d70b50d356b6decf6659c4d56 (excl.)
  • affected from f6d0775119fb905fb02eafa98d575cf8ee792d46 to 075fce376cf852db9293481edce07c181a9b1f46 (excl.)
  • affected from f6d0775119fb905fb02eafa98d575cf8ee792d46 to f0b791a006512a48b6348494cb6960598fa99a58 (excl.)
  • affected from f6d0775119fb905fb02eafa98d575cf8ee792d46 to aa9429edf9fc0e90d6f4da19ea4b5495a54ab117 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.0 is affected
  • unaffected from 0 to 6.0 (excl.)
  • unaffected from 6.6.151 to 6.6.* (incl.)
  • unaffected from 6.12.103 to 6.12.* (incl.)
  • unaffected from 6.18.44 to 6.18.* (incl.)
  • unaffected from 7.1.8 to 7.1.* (incl.)
  • unaffected from 7.2-rc6 to * (incl.)

References