{"id":"CVE-2026-98200","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show()\n\nnsensor->current_state is dynamically replaced as the sensor's state\nchanges","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show()\n\nnsensor->current_state is dynamically replaced as the sensor's state\nchanges. update_numeric_sensor_from_…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 23902f98f8d4811ab84dde6419569a5b374f8122 < b6b2a638aa36c441b2c8d0b6bd8ed2bb9701e795","Linux >= 23902f98f8d4811ab84dde6419569a5b374f8122 < f59ecfd2c58bace39538f3fff7f43788b3fdb539","Linux >= 23902f98f8d4811ab84dde6419569a5b374f8122 < 72c85149794a1ccf8d718ffed1521106b5d31968","Linux >= 23902f98f8d4811ab84dde6419569a5b374f8122 < 9c1e65bc79ff104914b11e6ad972139296ec86fe","Linux >= 23902f98f8d4811ab84dde6419569a5b374f8122 < e6cb0b4d4ecb8e71fd2200d907ab2e9663356f69","Linux 6.5"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T09:18:05.747","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98200","references":[{"url":"https://git.kernel.org/stable/c/72c85149794a1ccf8d718ffed1521106b5d31968","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9c1e65bc79ff104914b11e6ad972139296ec86fe","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b6b2a638aa36c441b2c8d0b6bd8ed2bb9701e795","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e6cb0b4d4ecb8e71fd2200d907ab2e9663356f69","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f59ecfd2c58bace39538f3fff7f43788b3fdb539","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T08:50:17.447Z","slug":"CVE-2026-98200","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show()\n\nnsensor->current_state is dynamically replaced as the sensor's state\nchanges. update_numeric_sensor_from_wobj() does this by freeing the\nold string and installing a new one:\n\n\tif (strcmp(trimmed, nsensor->current_state)) {\n\t\tnew_string = hp_wmi_strdup(dev, trimmed);\n\t\tif (new_string) {\n\t\t\tdevm_kfree(dev, nsensor->current_state);\n\t\t\tnsensor->current_state = new_string;\n\t\t}\n\t}\n\nThis function is only ever called from hp_wmi_update_info() while\nstate->lock is held, so the free-and-replace itself is properly\nserialized against concurrent updates.\n\nfungible_show(), however, reads the same pointer after the lock has\nalready been dropped:\n\n\terr = hp_wmi_update_info(state, info);\n\tif (err)\n\t\treturn err;\n\n\tswitch (prop) {\n\t...\n\tcase HP_WMI_PROPERTY_CURRENT_STATE:\n\t\tseq_printf(seqf, \"%s\\n\", nsensor->current_state);\n\t\tbreak;\n\nhp_wmi_update_info() takes state->lock internally and releases it\nbefore returning, so by the time fungible_show() dereferences\nnsensor->current_state in seq_printf(), no lock is held. Two\nprocesses reading a sensor's current_state debugfs entry at\noverlapping times (or one reading it while another read of the same\nsensor triggers a refresh) can race: one thread's seq_printf() can\nbe part-way through printing the string at the moment another\nthread's call into update_numeric_sensor_from_wobj() frees it with\ndevm_kfree() and installs a new pointer, causing a use-after-free\nread.\n\nTake state->lock around the read in fungible_show() as well, so it\ncan never run concurrently with the free-and-replace in\nupdate_numeric_sensor_from_wobj().\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}