{"id":"AZL-96252","summary":"CVE-2026-74552 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (lm90) Only report alarms if driver is ready\n\nUserspace can read sysfs attributes before driver registration is complete,\nimmediately after devm_hwmon_device_register_with_info() has been called.\nAt that time, data-\u003ehwmon_dev is not yet initialized. This can trigger\na NULL pointer access since lm90_update_device() and with it\nlm90_update_alarms_locked() will be called. This call schedules\nreport_work and lm90_report_alarms(), which passes the still-NULL\ndata-\u003ehwmon_dev to hwmon_notify_event() and triggers a NULL pointer\ndereference.\n\nFix the problem by only scheduling the report and alert workers\ndata-\u003ehwmon_dev is set.","modified":"2026-08-30T05:26:50Z","published":"2026-08-15T13:18:00Z","upstream":["CVE-2026-74552"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74552"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-96252.json"}}],"schema_version":"1.9.0"}