CVE-2026-98200 PUBLISHED

hwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show()

Assigner: Linux
Reserved: 25.09.2026 Published: 06.10.2026 Updated: 06.10.2026

In the Linux kernel, the following vulnerability has been resolved:

hwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show()

nsensor->current_state is dynamically replaced as the sensor's state changes. update_numeric_sensor_from_wobj() does this by freeing the old string and installing a new one:

<pre>if (strcmp(trimmed, nsensor->current_state)) { new_string = hp_wmi_strdup(dev, trimmed); if (new_string) { devm_kfree(dev, nsensor->current_state); nsensor->current_state = new_string; } } </pre>

This function is only ever called from hp_wmi_update_info() while state->lock is held, so the free-and-replace itself is properly serialized against concurrent updates.

fungible_show(), however, reads the same pointer after the lock has already been dropped:

<pre>err = hp_wmi_update_info(state, info); if (err) return err; switch (prop) { ... case HP_WMI_PROPERTY_CURRENT_STATE: seq_printf(seqf, "%s\n", nsensor->current_state); break; </pre>

hp_wmi_update_info() takes state->lock internally and releases it before returning, so by the time fungible_show() dereferences nsensor->current_state in seq_printf(), no lock is held. Two processes reading a sensor's current_state debugfs entry at overlapping times (or one reading it while another read of the same sensor triggers a refresh) can race: one thread's seq_printf() can be part-way through printing the string at the moment another thread's call into update_numeric_sensor_from_wobj() frees it with devm_kfree() and installs a new pointer, causing a use-after-free read.

Take state->lock around the read in fungible_show() as well, so it can never run concurrently with the free-and-replace in update_numeric_sensor_from_wobj().

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 23902f98f8d4811ab84dde6419569a5b374f8122 to b6b2a638aa36c441b2c8d0b6bd8ed2bb9701e795 (excl.)
  • affected from 23902f98f8d4811ab84dde6419569a5b374f8122 to f59ecfd2c58bace39538f3fff7f43788b3fdb539 (excl.)
  • affected from 23902f98f8d4811ab84dde6419569a5b374f8122 to 72c85149794a1ccf8d718ffed1521106b5d31968 (excl.)
  • affected from 23902f98f8d4811ab84dde6419569a5b374f8122 to 9c1e65bc79ff104914b11e6ad972139296ec86fe (excl.)
  • affected from 23902f98f8d4811ab84dde6419569a5b374f8122 to e6cb0b4d4ecb8e71fd2200d907ab2e9663356f69 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.5 is affected
  • unaffected from 0 to 6.5 (excl.)
  • unaffected from 6.6.158 to 6.6.* (incl.)
  • unaffected from 6.12.112 to 6.12.* (incl.)
  • unaffected from 6.18.54 to 6.18.* (incl.)
  • unaffected from 7.2.8 to 7.2.* (incl.)
  • unaffected from 7.3-rc4 to * (incl.)

References