CVE-2026-74552 is a vulnerability in Linux Kernel
Published on August 15, 2026
hwmon: (lm90) Only report alarms if driver is ready
In the Linux kernel, the following vulnerability has been resolved:
hwmon: (lm90) Only report alarms if driver is ready
Userspace can read sysfs attributes before driver registration is complete,
immediately after devm_hwmon_device_register_with_info() has been called.
At that time, data->hwmon_dev is not yet initialized. This can trigger
a NULL pointer access since lm90_update_device() and with it
lm90_update_alarms_locked() will be called. This call schedules
report_work and lm90_report_alarms(), which passes the still-NULL
data->hwmon_dev to hwmon_notify_event() and triggers a NULL pointer
dereference.
Fix the problem by only scheduling the report and alert workers
data->hwmon_dev is set.
Products Associated with CVE-2026-74552
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version f6d0775119fb905fb02eafa98d575cf8ee792d46 and below 4eed33c7db5c0c573928d28d8a2c003642c679b8 is affected.
- Version f6d0775119fb905fb02eafa98d575cf8ee792d46 and below 70d9a71aa407044d70b50d356b6decf6659c4d56 is affected.
- Version f6d0775119fb905fb02eafa98d575cf8ee792d46 and below 075fce376cf852db9293481edce07c181a9b1f46 is affected.
- Version f6d0775119fb905fb02eafa98d575cf8ee792d46 and below f0b791a006512a48b6348494cb6960598fa99a58 is affected.
- Version f6d0775119fb905fb02eafa98d575cf8ee792d46 and below aa9429edf9fc0e90d6f4da19ea4b5495a54ab117 is affected.
- Version 6.0 is affected.
- Before 6.0 is unaffected.
- Version 6.6.151, <= 6.6.* is unaffected.
- Version 6.12.103, <= 6.12.* is unaffected.
- Version 6.18.44, <= 6.18.* is unaffected.
- Version 7.1.8, <= 7.1.* is unaffected.
- Version 7.2-rc6, <= * is unaffected.