{"id":"CVE-2026-74552","summary":"hwmon: (lm90) Only report alarms if driver is ready","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (lm90) Only report alarms if driver is ready\n\nUserspace can read sysfs attributes before driver registration is complete,\nimmediately after devm_hwmon_device_register_with_info() has been called.\nAt that time, data-\u003ehwmon_dev is not yet initialized. This can trigger\na NULL pointer access since lm90_update_device() and with it\nlm90_update_alarms_locked() will be called. This call schedules\nreport_work and lm90_report_alarms(), which passes the still-NULL\ndata-\u003ehwmon_dev to hwmon_notify_event() and triggers a NULL pointer\ndereference.\n\nFix the problem by only scheduling the report and alert workers\ndata-\u003ehwmon_dev is set.","modified":"2026-08-21T03:30:28.005047414Z","published":"2026-08-15T12:27:58.829Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74552.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/075fce376cf852db9293481edce07c181a9b1f46"},{"type":"WEB","url":"https://git.kernel.org/stable/c/31ce62d36d859423dc39f9902f7c4c307b2e00e3"},{"type":"WEB","url":"https://git.kernel.org/stable/c/4eed33c7db5c0c573928d28d8a2c003642c679b8"},{"type":"WEB","url":"https://git.kernel.org/stable/c/70d9a71aa407044d70b50d356b6decf6659c4d56"},{"type":"WEB","url":"https://git.kernel.org/stable/c/aa9429edf9fc0e90d6f4da19ea4b5495a54ab117"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f0b791a006512a48b6348494cb6960598fa99a58"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74552.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74552"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"f6d0775119fb905fb02eafa98d575cf8ee792d46"},{"fixed":"31ce62d36d859423dc39f9902f7c4c307b2e00e3"},{"fixed":"4eed33c7db5c0c573928d28d8a2c003642c679b8"},{"fixed":"70d9a71aa407044d70b50d356b6decf6659c4d56"},{"fixed":"075fce376cf852db9293481edce07c181a9b1f46"},{"fixed":"f0b791a006512a48b6348494cb6960598fa99a58"},{"fixed":"aa9429edf9fc0e90d6f4da19ea4b5495a54ab117"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74552.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.0.0"},{"fixed":"6.1.183"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.151"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.103"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.44"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.1.8"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74552.json"}}],"schema_version":"1.9.0"}