← All Advisories

Linux Kernel hwmon w83791d Leaves fan/pwm sysfs Entries Present After Driver Unbind, Enabling a Local Use-After-Free

Last refreshed2026-10-10

Status: UPDATED  |  Advisory ID: CVE-2026-98197

Key Details

CVECVE-2026-98197
CVSS Score / Version7.0 (High) / CVSS v3.1
Updated2026-10-07
CVSS VectorCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is high; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Kernel

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux Kernel
SubsystemsOT Supporting Infrastructure
SectorsAll Sectors

What to Know

In the Linux kernel, the following vulnerability has been resolved:

hwmon: (w83791d) remove fan/pwm 4-5 sysfs group on remove

When the fan/pwm 4-5 pins are not used as GPIO, w83791d_probe()

creates the w83791d_group_fanpwm45 sysfs group on the I2C client

device.

The probe error path removes this group when a later initialization

step fails, but the normal remove path only removes w83791d_group.

As a result, the optional fan/pwm 4-5 sysfs files can remain after the

driver is unbound.

The callbacks associated with these files access the driver data,

which is devm allocated and released after driver unbind. Leaving the

sysfs files behind can therefore result in accesses to stale driver

data.

Remove w83791d_group_fanpwm45 during normal teardown as well.

This issue was found by manual code inspection. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-98197
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-98197