{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-92504","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-16T12:21:13.872Z","datePublished":"2026-09-17T16:10:16.731Z","dateUpdated":"2026-09-18T17:55:29.519Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:55:29.519Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nthermal: intel: int3400: clean up ODVP on probe failures\n\nevaluate_odvp() creates per-ODVP sysfs files before the thermal zone\nand later probe resources are registered. The current unwind path only\ncalls cleanup_odvp() from the late sysfs failure path, so failures after\nevaluate_odvp() but before that label, including\nthermal_tripless_zone_device_register() failures, leave the ODVP files\nand storage behind.\n\nMove the ODVP cleanup to the common ART/TRT unwind path so every failure\nafter evaluate_odvp() releases the ODVP state. Also clear the cached\nODVP pointers in cleanup_odvp(), because evaluate_odvp() can already call\nit for partial setup failures while probe continues."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - evaluate_odvp() in int3400_thermal_probe() creates odvpN attributes on the INT3400/INTC104x ACPI platform device; after a failed unwind the UAF is hit by reading those files in odvp_show(), not by a network or radio protocol payload.\nAC:H - The leak runs only when int3400_thermal_probe() fails after evaluate_odvp() but before the old free_sysfs label (thermal_tripless_zone_device_register(), sysfs_create_group() for uuids/imok, or device_create_bin_file()), or when evaluate_odvp() itself fails after allocating attrs; those are -ENOMEM/kernfs errors the attacker cannot force.\nPR:L - evaluate_odvp() creates each odvpN with mode 0444 on priv->pdev->dev.kobj; after probe kfree(priv) via free_art_trt without cleanup_odvp(), an unprivileged local user can open those leftover files and run odvp_show() with no CAP_SYS_ADMIN.\nUI:N - The attacker reads the leftover odvpN sysfs attributes themselves; no other user must mount media, bind int3400_thermal, or confirm a prompt.\nS:U - odvp_show() dereferences the probe-freed int3400_thermal_priv in the host kernel; this is not a VM, IOMMU, or sandbox escape.\nC:H - odvp_show() evaluates odvp_attr->priv->odvp[odvp_attr->odvp] after int3400_thermal_probe() kfree(priv) on free_art_trt, a slab UAF of int3400_thermal_priv that discloses kernel memory once that object is reclaimed.\nI:H - cleanup_odvp() used to leave priv->odvp/priv->odvp_attrs set after evaluate_odvp()'s out_err path; a later evaluate_odvp() from int3400_thermal_change_mode() or INT3400_ODVP_CHANGED then writes ACPI integers through the freed odvp buffer, and remove-path cleanup_odvp() double-frees it.\nA:H - odvp_show() dereferencing the freed priv, and evaluate_odvp() writing through a dangling priv->odvp, oops or panic the kernel."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/thermal/intel/int340x_thermal/int3400_thermal.c"],"versions":[{"version":"006f006f1e5c48e5ddd6515eab2c9a7b27ce1144","lessThan":"5798c714fccf1b4939a98a812b9073da365172c8","status":"affected","versionType":"git"},{"version":"006f006f1e5c48e5ddd6515eab2c9a7b27ce1144","lessThan":"bfd6df12ce6781e4bf1c7177dab42a8780177960","status":"affected","versionType":"git"},{"version":"006f006f1e5c48e5ddd6515eab2c9a7b27ce1144","lessThan":"ad13e550ce51c66560bafd315eb5d09f2ee7c4ce","status":"affected","versionType":"git"},{"version":"006f006f1e5c48e5ddd6515eab2c9a7b27ce1144","lessThan":"08df725b927512fa9672b146a00766da478b6c2e","status":"affected","versionType":"git"},{"version":"006f006f1e5c48e5ddd6515eab2c9a7b27ce1144","lessThan":"bc0e96267a6715fcc4b81cf980034a5e65703780","status":"affected","versionType":"git"},{"version":"006f006f1e5c48e5ddd6515eab2c9a7b27ce1144","lessThan":"d7b025d3fdf3cf8b726ce1d13f434f57477972bb","status":"affected","versionType":"git"},{"version":"006f006f1e5c48e5ddd6515eab2c9a7b27ce1144","lessThan":"169772cd2147c517be5cfda2710d17f8c90d6f10","status":"affected","versionType":"git"},{"version":"006f006f1e5c48e5ddd6515eab2c9a7b27ce1144","lessThan":"d83dc9ce57a746a6dca28439bcc0575d26fa6986","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/thermal/intel/int340x_thermal/int3400_thermal.c"],"versions":[{"version":"5.8","status":"affected"},{"version":"0","lessThan":"5.8","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/5798c714fccf1b4939a98a812b9073da365172c8"},{"url":"https://git.kernel.org/stable/c/bfd6df12ce6781e4bf1c7177dab42a8780177960"},{"url":"https://git.kernel.org/stable/c/ad13e550ce51c66560bafd315eb5d09f2ee7c4ce"},{"url":"https://git.kernel.org/stable/c/08df725b927512fa9672b146a00766da478b6c2e"},{"url":"https://git.kernel.org/stable/c/bc0e96267a6715fcc4b81cf980034a5e65703780"},{"url":"https://git.kernel.org/stable/c/d7b025d3fdf3cf8b726ce1d13f434f57477972bb"},{"url":"https://git.kernel.org/stable/c/169772cd2147c517be5cfda2710d17f8c90d6f10"},{"url":"https://git.kernel.org/stable/c/d83dc9ce57a746a6dca28439bcc0575d26fa6986"}],"title":"thermal: intel: int3400: clean up ODVP on probe failures","x_generator":{"engine":"bippy-1.2.0"}}}}