{"id":"CVE-2026-97582","published":"2026-09-25T11:17:09.010","lastModified":"2026-09-25T11:17:09.010","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (gpio-fan) Fix use-after-free in alarm work\n\nfan_alarm_irq_handler() queues fan_data->alarm_work, but nothing\ncancels it.  fan_alarm_notify() dereferences fan_data and its hwmon\ndevice.  On unbind, devres frees the interrupt, which only waits for\nthe handler itself, and then releases the hwmon device and fan_data,\nso a pending fan_alarm_notify() can run after those frees.\n\nReplace INIT_WORK() with devm_work_autocancel(), registered before\ndevm_request_irq().  The devres cleanup then frees the interrupt\nfirst, so no new work can be queued, and cancels the work while\nfan_data and the hwmon device are still alive.\n\nThis issue was found by an in-house static analysis tool.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/30755d3a5782cd704c8921cac8ee66dffe4383ea","tags":[]},{"url":"https://git.kernel.org/stable/c/9b12bd724db9db318e3a68be17693583dc29a066","tags":[]},{"url":"https://git.kernel.org/stable/c/a2471ed17b0e6ff7bfb6b2ea8e6e5b04c309d293","tags":[]},{"url":"https://git.kernel.org/stable/c/c6ab7f855891877a16d2e2ddf0cd0305fd098a85","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}