{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-98197","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:25:14.324Z","datePublished":"2026-10-06T08:44:36.283Z","dateUpdated":"2026-10-07T06:49:29.394Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-07T06:49:29.394Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (w83791d) remove fan/pwm 4-5 sysfs group on remove\n\nWhen the fan/pwm 4-5 pins are not used as GPIO, w83791d_probe()\ncreates the w83791d_group_fanpwm45 sysfs group on the I2C client\ndevice.\n\nThe probe error path removes this group when a later initialization\nstep fails, but the normal remove path only removes w83791d_group.\nAs a result, the optional fan/pwm 4-5 sysfs files can remain after the\ndriver is unbound.\n\nThe callbacks associated with these files access the driver data,\nwhich is devm allocated and released after driver unbind. Leaving the\nsysfs files behind can therefore result in accesses to stale driver\ndata.\n\nRemove w83791d_group_fanpwm45 during normal teardown as well.\n\nThis issue was found by manual code inspection."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The trigger is a local read (or write) of the w83791d_group_fanpwm45 files (fan4_input, fan5_input, pwm4, pwm5...) that w83791d_remove() left on the I2C client kobject. These are sysfs files on a local hwmon I2C chip; no remote protocol carries any data into this path.\nAC:H - The files only go stale after the driver is unbound or the module is unloaded, which takes real root via /sys/bus/i2c/drivers/w83791d/unbind or rmmod. It also needs W83791D hardware with fan4/5 pins not set as GPIO (GPIO reg bit 0x10). The attacker cannot arrange either and can only wait for them.\nPR:L - Once the files are stale, fan4_input/fan5_input and the other fanpwm45 show attributes are S_IRUGO, so any unprivileged local user can read them and reach show_fan() -> w83791d_update_device(). The 0644 store attributes stay root-only.\nUI:N - Apart from the admin unbind already counted under AC, the attacker only needs to read the stale sysfs attributes. No victim has to open a file, mount anything or take any other action.\nS:U - The stale accesses corrupt kernel memory (devm-allocated w83791d_data or freed module text/data) in the same kernel that hosts the driver. No VM, IOMMU or sandbox boundary is crossed.\nC:H - A read racing unbind's devres_release_all() runs w83791d_update_device() on the freed devm w83791d_data, which is a use-after-free of a kmalloc object. After rmmod, the leftover kernfs nodes point to freed module attribute structs and show callbacks. Either can be groomed into a memory disclosure.\nI:H - w83791d_update_device() writes register values into the freed object (data->in[], fan[], fan_min[], valid, last_updated) after taking its mutex, which is a UAF write. After rmmod, the stale attributes make an indirect call through freed module memory, a possible control-flow hijack if that memory is reallocated.\nA:H - Once unbind has set drvdata to NULL, any user reading fan4_input calls mutex_lock(&data->update_lock) on a NULL pointer and the kernel oopses. After module unload, reading the attribute jumps into unmapped module memory. Both can be repeated at will."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/hwmon/w83791d.c"],"versions":[{"version":"6e1ecd9b8f1358ed4d099f0c54434240dc40debe","lessThan":"081e3a78453635fb370b1712809d2af29e60b4c5","status":"affected","versionType":"git"},{"version":"6e1ecd9b8f1358ed4d099f0c54434240dc40debe","lessThan":"b1d419eb3bc41245c3d3d99dfe1a7b6c45989586","status":"affected","versionType":"git"},{"version":"6e1ecd9b8f1358ed4d099f0c54434240dc40debe","lessThan":"2ccf6c512290a288a2d4d7f076430dfb0c6ee476","status":"affected","versionType":"git"},{"version":"6e1ecd9b8f1358ed4d099f0c54434240dc40debe","lessThan":"f6e2ab72f32d16d71a2549c7ea062dd209f71670","status":"affected","versionType":"git"},{"version":"6e1ecd9b8f1358ed4d099f0c54434240dc40debe","lessThan":"2dd37d00f1f1af8e02ffa70ee573c10fd1a76864","status":"affected","versionType":"git"},{"version":"6e1ecd9b8f1358ed4d099f0c54434240dc40debe","lessThan":"2c381e6e0f033f2df13bd64905e7232c42f49009","status":"affected","versionType":"git"},{"version":"6e1ecd9b8f1358ed4d099f0c54434240dc40debe","lessThan":"583e04e88e75b8d57304015d83c38e82a9531600","status":"affected","versionType":"git"},{"version":"6e1ecd9b8f1358ed4d099f0c54434240dc40debe","lessThan":"0ff9c7775e51ac6d47b1bb5c46f06b1434fe58a8","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/hwmon/w83791d.c"],"versions":[{"version":"2.6.28","status":"affected"},{"version":"0","lessThan":"2.6.28","status":"unaffected","versionType":"semver"},{"version":"5.10.271","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.222","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.112","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.54","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.8","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc4","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.28","versionEndExcluding":"5.10.271"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.28","versionEndExcluding":"5.15.222"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.28","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.28","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.28","versionEndExcluding":"6.12.112"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.28","versionEndExcluding":"6.18.54"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.28","versionEndExcluding":"7.2.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.28","versionEndExcluding":"7.3-rc4"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/081e3a78453635fb370b1712809d2af29e60b4c5"},{"url":"https://git.kernel.org/stable/c/b1d419eb3bc41245c3d3d99dfe1a7b6c45989586"},{"url":"https://git.kernel.org/stable/c/2ccf6c512290a288a2d4d7f076430dfb0c6ee476"},{"url":"https://git.kernel.org/stable/c/f6e2ab72f32d16d71a2549c7ea062dd209f71670"},{"url":"https://git.kernel.org/stable/c/2dd37d00f1f1af8e02ffa70ee573c10fd1a76864"},{"url":"https://git.kernel.org/stable/c/2c381e6e0f033f2df13bd64905e7232c42f49009"},{"url":"https://git.kernel.org/stable/c/583e04e88e75b8d57304015d83c38e82a9531600"},{"url":"https://git.kernel.org/stable/c/0ff9c7775e51ac6d47b1bb5c46f06b1434fe58a8"}],"title":"hwmon: (w83791d) remove fan/pwm 4-5 sysfs group on remove","x_generator":{"engine":"bippy-1.2.0"}}}}