{"id":"CVE-2026-98200","summary":"hwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show()","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show()\n\nnsensor-\u003ecurrent_state is dynamically replaced as the sensor's state\nchanges. update_numeric_sensor_from_wobj() does this by freeing the\nold string and installing a new one:\n\n\tif (strcmp(trimmed, nsensor-\u003ecurrent_state)) {\n\t\tnew_string = hp_wmi_strdup(dev, trimmed);\n\t\tif (new_string) {\n\t\t\tdevm_kfree(dev, nsensor-\u003ecurrent_state);\n\t\t\tnsensor-\u003ecurrent_state = new_string;\n\t\t}\n\t}\n\nThis function is only ever called from hp_wmi_update_info() while\nstate-\u003elock is held, so the free-and-replace itself is properly\nserialized against concurrent updates.\n\nfungible_show(), however, reads the same pointer after the lock has\nalready been dropped:\n\n\terr = hp_wmi_update_info(state, info);\n\tif (err)\n\t\treturn err;\n\n\tswitch (prop) {\n\t...\n\tcase HP_WMI_PROPERTY_CURRENT_STATE:\n\t\tseq_printf(seqf, \"%s\\n\", nsensor-\u003ecurrent_state);\n\t\tbreak;\n\nhp_wmi_update_info() takes state-\u003elock internally and releases it\nbefore returning, so by the time fungible_show() dereferences\nnsensor-\u003ecurrent_state in seq_printf(), no lock is held. Two\nprocesses reading a sensor's current_state debugfs entry at\noverlapping times (or one reading it while another read of the same\nsensor triggers a refresh) can race: one thread's seq_printf() can\nbe part-way through printing the string at the moment another\nthread's call into update_numeric_sensor_from_wobj() frees it with\ndevm_kfree() and installs a new pointer, causing a use-after-free\nread.\n\nTake state-\u003elock around the read in fungible_show() as well, so it\ncan never run concurrently with the free-and-replace in\nupdate_numeric_sensor_from_wobj().","modified":"2026-10-08T02:52:53.469377884Z","published":"2026-10-06T08:44:38.289Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98200.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/72c85149794a1ccf8d718ffed1521106b5d31968"},{"type":"WEB","url":"https://git.kernel.org/stable/c/9c1e65bc79ff104914b11e6ad972139296ec86fe"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b6b2a638aa36c441b2c8d0b6bd8ed2bb9701e795"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e6cb0b4d4ecb8e71fd2200d907ab2e9663356f69"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f59ecfd2c58bace39538f3fff7f43788b3fdb539"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98200.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98200"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"23902f98f8d4811ab84dde6419569a5b374f8122"},{"fixed":"b6b2a638aa36c441b2c8d0b6bd8ed2bb9701e795"},{"fixed":"f59ecfd2c58bace39538f3fff7f43788b3fdb539"},{"fixed":"72c85149794a1ccf8d718ffed1521106b5d31968"},{"fixed":"9c1e65bc79ff104914b11e6ad972139296ec86fe"},{"fixed":"e6cb0b4d4ecb8e71fd2200d907ab2e9663356f69"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98200.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.5.0"},{"fixed":"6.6.158"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.112"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.54"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.2.8"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98200.json"}}],"schema_version":"1.9.0"}