{"id":"AZL-106149","summary":"CVE-2026-98200 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show()\n\nnsensor-\u003ecurrent_state is dynamically replaced as the sensor's state\nchanges. update_numeric_sensor_from_wobj() does this by freeing the\nold string and installing a new one:\n\n\tif (strcmp(trimmed, nsensor-\u003ecurrent_state)) {\n\t\tnew_string = hp_wmi_strdup(dev, trimmed);\n\t\tif (new_string) {\n\t\t\tdevm_kfree(dev, nsensor-\u003ecurrent_state);\n\t\t\tnsensor-\u003ecurrent_state = new_string;\n\t\t}\n\t}\n\nThis function is only ever called from hp_wmi_update_info() while\nstate-\u003elock is held, so the free-and-replace itself is properly\nserialized against concurrent updates.\n\nfungible_show(), however, reads the same pointer after the lock has\nalready been dropped:\n\n\terr = hp_wmi_update_info(state, info);\n\tif (err)\n\t\treturn err;\n\n\tswitch (prop) {\n\t...\n\tcase HP_WMI_PROPERTY_CURRENT_STATE:\n\t\tseq_printf(seqf, \"%s\\n\", nsensor-\u003ecurrent_state);\n\t\tbreak;\n\nhp_wmi_update_info() takes state-\u003elock internally and releases it\nbefore returning, so by the time fungible_show() dereferences\nnsensor-\u003ecurrent_state in seq_printf(), no lock is held. Two\nprocesses reading a sensor's current_state debugfs entry at\noverlapping times (or one reading it while another read of the same\nsensor triggers a refresh) can race: one thread's seq_printf() can\nbe part-way through printing the string at the moment another\nthread's call into update_numeric_sensor_from_wobj() frees it with\ndevm_kfree() and installs a new pointer, causing a use-after-free\nread.\n\nTake state-\u003elock around the read in fungible_show() as well, so it\ncan never run concurrently with the free-and-replace in\nupdate_numeric_sensor_from_wobj().","modified":"2026-10-08T05:35:32Z","published":"2026-10-06T09:18:05Z","upstream":["CVE-2026-98200"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98200"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106149.json"}}],"schema_version":"1.9.0"}