Answer in brief
CVE-2026-98200 records a Unknown severity vulnerability in hwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=23902f98f8d4811ab84dde6419569a5b374f8122 <b6b2a638aa36c441b2c8d0b6bd8ed2bb9701e795 || >=23902f98f8d4811ab84dde6419569a5b374f8122 <f59ecfd2c58bace39538f3fff7f43788b3fdb539 || >=23902f98f8d4811ab84dde6419569a5b374f8122 <72c85149794a1ccf8d718ffed1521106b5d31968 || >=23902f98f8d4811ab84dde6419569a5b374f8122 <9c1e65bc79ff104914b11e6ad972139296ec86fe || >=23902f98f8d4811ab84dde6419569a5b374f8122 <e6cb0b4d4ecb8e71fd2200d907ab2e9663356f69 | b6b2a638aa36c441b2c8d0b6bd8ed2bb9701e795, f59ecfd2c58bace39538f3fff7f43788b3fdb539, 72c85149794a1ccf8d718ffed1521106b5d31968, 9c1e65bc79ff104914b11e6ad972139296ec86fe, e6cb0b4d4ecb8e71fd2200d907ab2e9663356f69 |
| Linux/Linuxgeneric | 6.5 | Not reported |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
In the Linux kernel, the following vulnerability has been resolved: hwmon: (hp-wmi-sensors) Fix use-after-free in fungible_show() nsensor->current_state is dynamically replaced as the sensor's state changes. update_numeric_sensor_from_wobj() does this by freeing the old string and installing a new one: if (strcmp(trimmed, nsensor->current_state)) { new_string = hp_wmi_strdup(dev, trimmed); if (new_string) { devm_kfree(dev, nsensor->current_state); nsensor->current_state = new_string; } } This function is only ever called from hp_wmi_update_info() while state->lock is held, so the free-and-replace itself is properly serialized against concurrent updates. fungible_show(), however, reads the same pointer after the lock has already been dropped: err = hp_wmi_update_info(state, info); if (err) return err; switch (prop) { ... case HP_WMI_PROPERTY_CURRENT_STATE: seq_printf(seqf, "%s\n", nsensor->current_state); break; hp_wmi_update_info() takes state->lock internally and releases it before returning, so by the time fungible_show() dereferences nsensor->current_state in seq_printf(), no lock is held. Two processes reading a sensor's current_state debugfs entry at overlapping times (or one reading it while another read of the same sensor triggers a refresh) can race: one thread's seq_printf() can be part-way through printing the string at the moment another thread's call into update_numeric_sensor_from_wobj() frees it with devm_kfree() and installs a new pointer, causing a use-after-free read. Take state->lock around the read in fungible_show() as well, so it can never run concurrently with the free-and-replace in update_numeric_sensor_from_wobj().
Quoted source text, attributed separately from HOL analysis.