Sceawere
Vulnerability Detail
CVE-2026-98197UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Use-After-Free in w83791d Driver
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7
- Creation Date
- 1d ago
- Vendor
- Linux
- Product
- Linux
- Attack Type
- N/A
- Vector String
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
In the Linux kernel, the following vulnerability has been resolved: hwmon: (w83791d) remove fan/pwm 4-5 sysfs group on remove When the fan/pwm 4-5 pins are not used as GPIO, w83791d_probe() creates the w83791d_group_fanpwm45 sysfs group on the I2C client device. The probe error path removes this group when a later initialization step fails, but the normal remove path only removes w83791d_group. As a result, the optional fan/pwm 4-5 sysfs files can remain after the driver is unbound. The callbacks associated with these files access the driver data, which is devm allocated and released after driver unbind. Leaving the sysfs files behind can therefore result in accesses to stale driver data. Remove w83791d_group_fanpwm45 during normal teardown as well. This issue was found by manual code inspection.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.0",
"pubDate": "2026-10-06T09:18:05.273Z",
"pubdate": "2026-10-06T09:18:05.273Z",
"executiveSummary": "The Linux kernel hwmon: w83791d driver suffers from a Use-After-Free vulnerability due to improper management of sysfs groups during device teardown.\nThe vulnerability stems from the driver failing to remove the 'w83791d_group_fanpwm45' sysfs group during the normal device unbind/remove operation.\nThis leaves stale sysfs entries exposed after the underlying driver data, managed via devm (managed device resources), has been released.\nAn attacker with local access could potentially trigger a read or write operation on these orphaned sysfs files, leading to a Use-After-Free condition.\nThis exploitation could result in kernel memory corruption, arbitrary code execution, or a system panic (Denial of Service).\nThe vulnerability affects the w83791d hardware monitoring driver within the Linux kernel where fan/pwm pins 4-5 are utilized.\nSuccessful exploitation requires local access to the filesystem to interact with the sysfs interface.",
"technicalDetails": "The root cause of this vulnerability is an inconsistent teardown sequence within the w83791d hardware monitoring driver. During the driver probe process (w83791d_probe), if the fan/pwm 4-5 pins are not configured as GPIO, the driver registers an additional sysfs group named 'w83791d_group_fanpwm45' associated with the I2C client device.\nWhile the probe error handling path correctly accounts for the removal of this group if subsequent initialization steps fail, the standard remove path (driver unbind) only removes the primary 'w83791d_group'. Consequently, if the driver is unbound from the hardware device, the 'w83791d_group_fanpwm45' sysfs entries persist in the sysfs filesystem.\nThese persistent sysfs files contain callback pointers that refer to driver-specific data structures. Since the driver utilizes devm-allocated resources, the associated data is automatically freed once the device is unbound. Because the sysfs files are not properly removed, subsequent user-space interaction with these files invokes the callbacks, which attempt to access the now-invalid memory addresses pointing to the deallocated driver data.\nThe attack flow involves the following sequence: 1) The attacker triggers the removal or unbinding of the w83791d driver. 2) The kernel completes the unbind process, releasing all devm-managed resources, including the state structures used by the driver. 3) The attacker identifies that the 'w83791d_group_fanpwm45' sysfs nodes remain active under the I2C client device path. 4) The attacker issues a read or write system call to one of the orphaned sysfs files. 5) The kernel executes the driver's registered callback function, which dereferences a pointer to the already freed driver data, resulting in a Use-After-Free.\nThe impact of this Use-After-Free is critical, as it allows an attacker to manipulate kernel-level memory. Depending on the kernel's memory allocation state, an attacker might be able to groom the heap to replace the freed object with malicious data, potentially leading to arbitrary code execution or privilege escalation. If memory grooming is not successful, the access will likely result in a kernel panic, causing a Denial of Service."
}