CVE-2026-97582
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
25/09/2026
Última modificación:
25/09/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
hwmon: (gpio-fan) Fix use-after-free in alarm work<br />
<br />
fan_alarm_irq_handler() queues fan_data->alarm_work, but nothing<br />
cancels it. fan_alarm_notify() dereferences fan_data and its hwmon<br />
device. On unbind, devres frees the interrupt, which only waits for<br />
the handler itself, and then releases the hwmon device and fan_data,<br />
so a pending fan_alarm_notify() can run after those frees.<br />
<br />
Replace INIT_WORK() with devm_work_autocancel(), registered before<br />
devm_request_irq(). The devres cleanup then frees the interrupt<br />
first, so no new work can be queued, and cancels the work while<br />
fan_data and the hwmon device are still alive.<br />
<br />
This issue was found by an in-house static analysis tool.


