Answer in brief
CVE-2026-74552 records a Unknown severity vulnerability in hwmon: (lm90) Only report alarms if driver is ready. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=f6d0775119fb905fb02eafa98d575cf8ee792d46 <4eed33c7db5c0c573928d28d8a2c003642c679b8 || >=f6d0775119fb905fb02eafa98d575cf8ee792d46 <70d9a71aa407044d70b50d356b6decf6659c4d56 || >=f6d0775119fb905fb02eafa98d575cf8ee792d46 <075fce376cf852db9293481edce07c181a9b1f46 || >=f6d0775119fb905fb02eafa98d575cf8ee792d46 <f0b791a006512a48b6348494cb6960598fa99a58 || >=f6d0775119fb905fb02eafa98d575cf8ee792d46 <aa9429edf9fc0e90d6f4da19ea4b5495a54ab117 | 4eed33c7db5c0c573928d28d8a2c003642c679b8, 70d9a71aa407044d70b50d356b6decf6659c4d56, 075fce376cf852db9293481edce07c181a9b1f46, f0b791a006512a48b6348494cb6960598fa99a58, aa9429edf9fc0e90d6f4da19ea4b5495a54ab117 |
| Linux/Linuxgeneric | 6.0 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: hwmon: (lm90) Only report alarms if driver is ready Userspace can read sysfs attributes before driver registration is complete, immediately after devm_hwmon_device_register_with_info() has been called. At that time, data->hwmon_dev is not yet initialized. This can trigger a NULL pointer access since lm90_update_device() and with it lm90_update_alarms_locked() will be called. This call schedules report_work and lm90_report_alarms(), which passes the still-NULL data->hwmon_dev to hwmon_notify_event() and triggers a NULL pointer dereference. Fix the problem by only scheduling the report and alert workers data->hwmon_dev is set.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-74552 records a Unknown severity vulnerability in hwmon: (lm90) Only report alarms if driver is ready. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=f6d0775119fb905fb02eafa98d575cf8ee792d46 <4eed33c7db5c0c573928d28d8a2c003642c679b8 || >=f6d0775119fb905fb02eafa98d575cf8ee792d46 <70d9a71aa407044d70b50d356b6decf6659c4d56 || >=f6d0775119fb905fb02eafa98d575cf8ee792d46 <075fce376cf852db9293481edce07c181a9b1f46 || >=f6d0775119fb905fb02eafa98d575cf8ee792d46 <f0b791a006512a48b6348494cb6960598fa99a58 || >=f6d0775119fb905fb02eafa98d575cf8ee792d46 <aa9429edf9fc0e90d6f4da19ea4b5495a54ab117 | 4eed33c7db5c0c573928d28d8a2c003642c679b8, 70d9a71aa407044d70b50d356b6decf6659c4d56, 075fce376cf852db9293481edce07c181a9b1f46, f0b791a006512a48b6348494cb6960598fa99a58, aa9429edf9fc0e90d6f4da19ea4b5495a54ab117 |
| Linux/Linuxgeneric | 6.0 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: hwmon: (lm90) Only report alarms if driver is ready Userspace can read sysfs attributes before driver registration is complete, immediately after devm_hwmon_device_register_with_info() has been called. At that time, data->hwmon_dev is not yet initialized. This can trigger a NULL pointer access since lm90_update_device() and with it lm90_update_alarms_locked() will be called. This call schedules report_work and lm90_report_alarms(), which passes the still-NULL data->hwmon_dev to hwmon_notify_event() and triggers a NULL pointer dereference. Fix the problem by only scheduling the report and alert workers data->hwmon_dev is set.
Quoted source text, attributed separately from HOL analysis.