CVE-2026-74552

UnknownEPSS 0.17%

Last modified

CVE-2026-74552 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: hwmon: (lm90) Only report alarms if driver is ready Userspace can read sysfs attributes before driver registration is complete, immediately after devm_hwmon_device_register_with_info() has been called. At that time, data->hwmon_dev is not yet initialized. This can trigger a NULL pointer access since lm90_update_device() and with it lm90_update_alarms_locked() will be called. EPSS estimates a 0.17% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: hwmon: (lm90) Only report alarms if driver is ready Userspace can read sysfs attributes before driver registration is complete, immediately after devm_hwmon_device_register_with_info() has been called. At that time, data->hwmon_dev is not yet initialized. This can trigger a NULL pointer access since lm90_update_device() and with it lm90_update_alarms_locked() will be called. This call schedules report_work and lm90_report_alarms(), which passes the still-NULL data->hwmon_dev to hwmon_notify_event() and triggers a NULL pointer dereference. Fix the problem by only scheduling the report and alert workers data->hwmon_dev is set.

Metrics

EPSS Probability
0.17%

6.5th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= f6d0775119fb905fb02eafa98d575cf8ee792d46, < 31ce62d36d859423dc39f9902f7c4c307b2e00e3; >= f6d0775119fb905fb02eafa98d575cf8ee792d46, < 4eed33c7db5c0c573928d28d8a2c003642c679b8; >= f6d0775119fb905fb02eafa98d575cf8ee792d46, < 70d9a71aa407044d70b50d356b6decf6659c4d56; >= f6d0775119fb905fb02eafa98d575cf8ee792d46, < 075fce376cf852db9293481edce07c181a9b1f46; >= f6d0775119fb905fb02eafa98d575cf8ee792d46, < f0b791a006512a48b6348494cb6960598fa99a58; >= f6d0775119fb905fb02eafa98d575cf8ee792d46, < aa9429edf9fc0e90d6f4da19ea4b5495a54ab117
LinuxLinux6.0

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-74552?
In the Linux kernel, the following vulnerability has been resolved: hwmon: (lm90) Only report alarms if driver is ready Userspace can read sysfs attributes before driver registration is complete, immediately after devm_hwmon_device_register_with_info() has been called. At that time, data->hwmon_dev is not yet initialized. This can trigger a NULL pointer access since lm90_update_device() and with it lm90_update_alarms_locked() will be called. This call schedules report_work and lm90_report_alarms(), which passes the still-NULL data->hwmon_dev to hwmon_notify_event() and triggers a NULL pointer dereference. Fix the problem by only scheduling the report and alert workers data->hwmon_dev is set.
How severe is CVE-2026-74552?
Severity scoring for CVE-2026-74552 is pending analysis. The EPSS model estimates a 0.17% probability of exploitation in the next 30 days.
How do I fix CVE-2026-74552?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-74552?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST