CVE-2026-74552
In the Linux kernel, the following vulnerability has been resolved: hwmon: (lm90) Only report alarms if driver is ready Userspace can read
CVSS
—
No CVSS
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Aug 15, 2026 · Last modified: Aug 15, 2026
Not enough EPSS history yet.
In the Linux kernel, the following vulnerability has been resolved: hwmon: (lm90) Only report alarms if driver is ready Userspace can read sysfs attributes before driver registration is complete, immediately after devm_hwmon_device_register_with_info() has been called. At that time, data->hwmon_dev is not yet initialized. This can trigger a NULL pointer access since lm90_update_device() and with it lm90_update_alarms_locked() will be called. This call schedules report_work and lm90_report_alarms(), which passes the still-NULL data->hwmon_dev to hwmon_notify_event() and triggers a NULL pointer dereference. Fix the problem by only scheduling the report and alert workers data->hwmon_dev is set.
- git.kernel.orghttps://git.kernel.org/stable/c/075fce376cf852db9293481edce07c181a9b1f46
- git.kernel.orghttps://git.kernel.org/stable/c/4eed33c7db5c0c573928d28d8a2c003642c679b8
- git.kernel.orghttps://git.kernel.org/stable/c/70d9a71aa407044d70b50d356b6decf6659c4d56
- git.kernel.orghttps://git.kernel.org/stable/c/aa9429edf9fc0e90d6f4da19ea4b5495a54ab117
- git.kernel.orghttps://git.kernel.org/stable/c/f0b791a006512a48b6348494cb6960598fa99a58
No related CVEs by CWE or product.