CVE-2026-74552

Source
https://cve.org/CVERecord?id=CVE-2026-74552
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74552.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74552
Downstream
Published
2026-08-15T12:27:58Z
Modified
2026-08-21T03:30:28Z
Summary
hwmon: (lm90) Only report alarms if driver is ready
Details

In the Linux kernel, the following vulnerability has been resolved:

hwmon: (lm90) Only report alarms if driver is ready

Userspace can read sysfs attributes before driver registration is complete, immediately after devm_hwmon_device_register_with_info() has been called. At that time, data->hwmon_dev is not yet initialized. This can trigger a NULL pointer access since lm90_update_device() and with it lm90_update_alarms_locked() will be called. This call schedules report_work and lm90_report_alarms(), which passes the still-NULL data->hwmon_dev to hwmon_notify_event() and triggers a NULL pointer dereference.

Fix the problem by only scheduling the report and alert workers data->hwmon_dev is set.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74552.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
f6d0775119fb905fb02eafa98d575cf8ee792d46
Fixed
31ce62d36d859423dc39f9902f7c4c307b2e00e3
Fixed
4eed33c7db5c0c573928d28d8a2c003642c679b8
Fixed
70d9a71aa407044d70b50d356b6decf6659c4d56
Fixed
075fce376cf852db9293481edce07c181a9b1f46
Fixed
f0b791a006512a48b6348494cb6960598fa99a58
Fixed
aa9429edf9fc0e90d6f4da19ea4b5495a54ab117

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74552.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.0.0
Fixed
6.1.183
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.151
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.103
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.44
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74552.json"