CVE-2026-98200 (GCVE-0-2026-98200)

Vulnerability from cvelistv5 – Published: 2026-10-06 08:44 – Updated: 2026-10-06 08:44
VLAI
Title
hwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show()
Summary
In the Linux kernel, the following vulnerability has been resolved: hwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show() nsensor->current_state is dynamically replaced as the sensor's state changes. update_numeric_sensor_from_wobj() does this by freeing the old string and installing a new one: if (strcmp(trimmed, nsensor->current_state)) { new_string = hp_wmi_strdup(dev, trimmed); if (new_string) { devm_kfree(dev, nsensor->current_state); nsensor->current_state = new_string; } } This function is only ever called from hp_wmi_update_info() while state->lock is held, so the free-and-replace itself is properly serialized against concurrent updates. fungible_show(), however, reads the same pointer after the lock has already been dropped: err = hp_wmi_update_info(state, info); if (err) return err; switch (prop) { ... case HP_WMI_PROPERTY_CURRENT_STATE: seq_printf(seqf, "%s\n", nsensor->current_state); break; hp_wmi_update_info() takes state->lock internally and releases it before returning, so by the time fungible_show() dereferences nsensor->current_state in seq_printf(), no lock is held. Two processes reading a sensor's current_state debugfs entry at overlapping times (or one reading it while another read of the same sensor triggers a refresh) can race: one thread's seq_printf() can be part-way through printing the string at the moment another thread's call into update_numeric_sensor_from_wobj() frees it with devm_kfree() and installs a new pointer, causing a use-after-free read. Take state->lock around the read in fungible_show() as well, so it can never run concurrently with the free-and-replace in update_numeric_sensor_from_wobj().
Severity
No CVSS data available.
Impacted products
Vendor Product Version
Linux Linux Affected: 23902f98f8d4811ab84dde6419569a5b374f8122 , < b6b2a638aa36c441b2c8d0b6bd8ed2bb9701e795 (git)
Affected: 23902f98f8d4811ab84dde6419569a5b374f8122 , < f59ecfd2c58bace39538f3fff7f43788b3fdb539 (git)
Affected: 23902f98f8d4811ab84dde6419569a5b374f8122 , < 72c85149794a1ccf8d718ffed1521106b5d31968 (git)
Affected: 23902f98f8d4811ab84dde6419569a5b374f8122 , < 9c1e65bc79ff104914b11e6ad972139296ec86fe (git)
Affected: 23902f98f8d4811ab84dde6419569a5b374f8122 , < e6cb0b4d4ecb8e71fd2200d907ab2e9663356f69 (git)
Create a notification for this product.
Linux Linux Affected: 6.5
Unaffected: 0 , < 6.5 (semver)
Unaffected: 6.6.158 , ≤ 6.6.* (semver)
Unaffected: 6.12.112 , ≤ 6.12.* (semver)
Unaffected: 6.18.54 , ≤ 6.18.* (semver)
Unaffected: 7.2.8 , ≤ 7.2.* (semver)
Unaffected: 7.3-rc4 , ≤ * (original_commit_for_fix)
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/hwmon/hp-wmi-sensors.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "b6b2a638aa36c441b2c8d0b6bd8ed2bb9701e795",
              "status": "affected",
              "version": "23902f98f8d4811ab84dde6419569a5b374f8122",
              "versionType": "git"
            },
            {
              "lessThan": "f59ecfd2c58bace39538f3fff7f43788b3fdb539",
              "status": "affected",
              "version": "23902f98f8d4811ab84dde6419569a5b374f8122",
              "versionType": "git"
            },
            {
              "lessThan": "72c85149794a1ccf8d718ffed1521106b5d31968",
              "status": "affected",
              "version": "23902f98f8d4811ab84dde6419569a5b374f8122",
              "versionType": "git"
            },
            {
              "lessThan": "9c1e65bc79ff104914b11e6ad972139296ec86fe",
              "status": "affected",
              "version": "23902f98f8d4811ab84dde6419569a5b374f8122",
              "versionType": "git"
            },
            {
              "lessThan": "e6cb0b4d4ecb8e71fd2200d907ab2e9663356f69",
              "status": "affected",
              "version": "23902f98f8d4811ab84dde6419569a5b374f8122",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/hwmon/hp-wmi-sensors.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.5"
            },
            {
              "lessThan": "6.5",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.2.*",
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.158",
                  "versionStartIncluding": "6.5",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.112",
                  "versionStartIncluding": "6.5",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.54",
                  "versionStartIncluding": "6.5",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.2.8",
                  "versionStartIncluding": "6.5",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.3-rc4",
                  "versionStartIncluding": "6.5",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show()\n\nnsensor-\u003ecurrent_state is dynamically replaced as the sensor\u0027s state\nchanges. update_numeric_sensor_from_wobj() does this by freeing the\nold string and installing a new one:\n\n\tif (strcmp(trimmed, nsensor-\u003ecurrent_state)) {\n\t\tnew_string = hp_wmi_strdup(dev, trimmed);\n\t\tif (new_string) {\n\t\t\tdevm_kfree(dev, nsensor-\u003ecurrent_state);\n\t\t\tnsensor-\u003ecurrent_state = new_string;\n\t\t}\n\t}\n\nThis function is only ever called from hp_wmi_update_info() while\nstate-\u003elock is held, so the free-and-replace itself is properly\nserialized against concurrent updates.\n\nfungible_show(), however, reads the same pointer after the lock has\nalready been dropped:\n\n\terr = hp_wmi_update_info(state, info);\n\tif (err)\n\t\treturn err;\n\n\tswitch (prop) {\n\t...\n\tcase HP_WMI_PROPERTY_CURRENT_STATE:\n\t\tseq_printf(seqf, \"%s\\n\", nsensor-\u003ecurrent_state);\n\t\tbreak;\n\nhp_wmi_update_info() takes state-\u003elock internally and releases it\nbefore returning, so by the time fungible_show() dereferences\nnsensor-\u003ecurrent_state in seq_printf(), no lock is held. Two\nprocesses reading a sensor\u0027s current_state debugfs entry at\noverlapping times (or one reading it while another read of the same\nsensor triggers a refresh) can race: one thread\u0027s seq_printf() can\nbe part-way through printing the string at the moment another\nthread\u0027s call into update_numeric_sensor_from_wobj() frees it with\ndevm_kfree() and installs a new pointer, causing a use-after-free\nread.\n\nTake state-\u003elock around the read in fungible_show() as well, so it\ncan never run concurrently with the free-and-replace in\nupdate_numeric_sensor_from_wobj()."
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-06T08:44:38.289Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b6b2a638aa36c441b2c8d0b6bd8ed2bb9701e795"
        },
        {
          "url": "https://git.kernel.org/stable/c/f59ecfd2c58bace39538f3fff7f43788b3fdb539"
        },
        {
          "url": "https://git.kernel.org/stable/c/72c85149794a1ccf8d718ffed1521106b5d31968"
        },
        {
          "url": "https://git.kernel.org/stable/c/9c1e65bc79ff104914b11e6ad972139296ec86fe"
        },
        {
          "url": "https://git.kernel.org/stable/c/e6cb0b4d4ecb8e71fd2200d907ab2e9663356f69"
        }
      ],
      "title": "hwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show()",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-98200",
    "datePublished": "2026-10-06T08:44:38.289Z",
    "dateReserved": "2026-09-25T10:25:14.324Z",
    "dateUpdated": "2026-10-06T08:44:38.289Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "epss": {
      "cve": "CVE-2026-98200",
      "date": "2026-10-09",
      "epss": "0.00175",
      "percentile": "0.06431"
    },
    "nvd": {
      "cve": {
        "affected": [
          {
            "affectedData": [
              {
                "defaultStatus": "unaffected",
                "product": "Linux",
                "programFiles": [
                  "drivers/hwmon/hp-wmi-sensors.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "lessThan": "b6b2a638aa36c441b2c8d0b6bd8ed2bb9701e795",
                    "status": "affected",
                    "version": "23902f98f8d4811ab84dde6419569a5b374f8122",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "f59ecfd2c58bace39538f3fff7f43788b3fdb539",
                    "status": "affected",
                    "version": "23902f98f8d4811ab84dde6419569a5b374f8122",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "72c85149794a1ccf8d718ffed1521106b5d31968",
                    "status": "affected",
                    "version": "23902f98f8d4811ab84dde6419569a5b374f8122",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "9c1e65bc79ff104914b11e6ad972139296ec86fe",
                    "status": "affected",
                    "version": "23902f98f8d4811ab84dde6419569a5b374f8122",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "e6cb0b4d4ecb8e71fd2200d907ab2e9663356f69",
                    "status": "affected",
                    "version": "23902f98f8d4811ab84dde6419569a5b374f8122",
                    "versionType": "git"
                  }
                ]
              },
              {
                "defaultStatus": "affected",
                "product": "Linux",
                "programFiles": [
                  "drivers/hwmon/hp-wmi-sensors.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.5"
                  },
                  {
                    "lessThan": "6.5",
                    "status": "unaffected",
                    "version": "0",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.6.*",
                    "status": "unaffected",
                    "version": "6.6.158",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.12.*",
                    "status": "unaffected",
                    "version": "6.12.112",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.18.*",
                    "status": "unaffected",
                    "version": "6.18.54",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "7.2.*",
                    "status": "unaffected",
                    "version": "7.2.8",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "*",
                    "status": "unaffected",
                    "version": "7.3-rc4",
                    "versionType": "original_commit_for_fix"
                  }
                ]
              }
            ],
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
          }
        ],
        "cveTags": [],
        "descriptions": [
          {
            "lang": "en",
            "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show()\n\nnsensor-\u003ecurrent_state is dynamically replaced as the sensor\u0027s state\nchanges. update_numeric_sensor_from_wobj() does this by freeing the\nold string and installing a new one:\n\n\tif (strcmp(trimmed, nsensor-\u003ecurrent_state)) {\n\t\tnew_string = hp_wmi_strdup(dev, trimmed);\n\t\tif (new_string) {\n\t\t\tdevm_kfree(dev, nsensor-\u003ecurrent_state);\n\t\t\tnsensor-\u003ecurrent_state = new_string;\n\t\t}\n\t}\n\nThis function is only ever called from hp_wmi_update_info() while\nstate-\u003elock is held, so the free-and-replace itself is properly\nserialized against concurrent updates.\n\nfungible_show(), however, reads the same pointer after the lock has\nalready been dropped:\n\n\terr = hp_wmi_update_info(state, info);\n\tif (err)\n\t\treturn err;\n\n\tswitch (prop) {\n\t...\n\tcase HP_WMI_PROPERTY_CURRENT_STATE:\n\t\tseq_printf(seqf, \"%s\\n\", nsensor-\u003ecurrent_state);\n\t\tbreak;\n\nhp_wmi_update_info() takes state-\u003elock internally and releases it\nbefore returning, so by the time fungible_show() dereferences\nnsensor-\u003ecurrent_state in seq_printf(), no lock is held. Two\nprocesses reading a sensor\u0027s current_state debugfs entry at\noverlapping times (or one reading it while another read of the same\nsensor triggers a refresh) can race: one thread\u0027s seq_printf() can\nbe part-way through printing the string at the moment another\nthread\u0027s call into update_numeric_sensor_from_wobj() frees it with\ndevm_kfree() and installs a new pointer, causing a use-after-free\nread.\n\nTake state-\u003elock around the read in fungible_show() as well, so it\ncan never run concurrently with the free-and-replace in\nupdate_numeric_sensor_from_wobj()."
          }
        ],
        "id": "CVE-2026-98200",
        "lastModified": "2026-10-06T09:18:05.747",
        "metrics": {},
        "published": "2026-10-06T09:18:05.747",
        "references": [
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/72c85149794a1ccf8d718ffed1521106b5d31968"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/9c1e65bc79ff104914b11e6ad972139296ec86fe"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/b6b2a638aa36c441b2c8d0b6bd8ed2bb9701e795"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/e6cb0b4d4ecb8e71fd2200d907ab2e9663356f69"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/f59ecfd2c58bace39538f3fff7f43788b3fdb539"
          }
        ],
        "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "vulnStatus": "Received"
      }
    },
    "redhat_vex": {
      "aggregate_severity": "Moderate",
      "current_release_date": "2026-10-08T23:35:29+00:00",
      "cve": "CVE-2026-98200",
      "id": "CVE-2026-98200",
      "initial_release_date": "2026-10-06T00:00:00+00:00",
      "product_status:known_not_affected": "277",
      "source": "Red Hat CSAF VEX",
      "status": "final",
      "title": "kernel: hwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show()",
      "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-98200.json",
      "version": "3"
    },
    "suse_vex": {
      "aggregate_severity": "low",
      "current_release_date": "2026-10-08T16:50:47Z",
      "cve": "CVE-2026-98200",
      "id": "CVE-2026-98200",
      "initial_release_date": "2026-10-08T16:50:47Z",
      "product_status:known_not_affected": "347",
      "source": "SUSE CSAF VEX",
      "status": "interim",
      "title": "SUSE CVE CVE-2026-98200",
      "url": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-98200.json",
      "version": "2"
    }
  }
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…