SEPTEMBER 23, 2026
Live Feed
Back to database
Case File

CVE-2026-74552

UNKNOWN · CVSS N/A EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-08-15 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

A vulnerability in the Linux kernel's hwmon subsystem allows userspace to access sysfs attributes before the driver is fully initialized, leading to a potential NULL pointer dereference. This can result in system instability or crashes when the lm90 driver attempts to report alarms prematurely. Organizations using affected Linux kernel versions should prioritize patching this vulnerability to ensure system reliability and prevent unexpected failures.

CVE
CVE-2026-74552
Severity
UNKNOWN
CVSS
N/A
EPSS
0.17%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: hwmon: (lm90) Only report alarms if driver is ready Userspace can read sysfs attributes before driver registration is complete, immediately after devm_hwmon_device_register_with_info() has been called. At that time, data->hwmon_dev is not yet initialized. This can trigger a NULL pointer access since lm90_update_device() and with it lm90_update_alarms_locked() will be called. This call schedules report_work and lm90_report_alarms(), which passes the still-NULL data->hwmon_dev to hwmon_notify_event() and triggers a NULL pointer dereference. Fix the problem by only scheduling the report and alert workers data->hwmon_dev is set.