CVE-2026-98198: hwmon: (pwm-fan) Stop RPM timer before freeing tach data

Published Oct 6, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

hwmon: (pwm-fan) Stop RPM timer before freeing tach data

sampletimer() rearms the RPM timer and accesses the devm-managed ctx->tachs and ctx->pulsesperrevolution arrays. The cleanup action which stops the timer is registered before those arrays are allocated.

Since devres releases entries in reverse order, driver detach can free the arrays before pwmfancleanup() shuts down the timer. A timer expiry in that window accesses the freed tach data.

With a KASAN kernel, a test-only kprobe delayed entry to pwmfancleanup() while normal sysfs unbind ran. Each of three runs reported three four-byte reads and two four-byte writes in sampletimer() after its backing devm allocations had been freed. The helper did not invoke the timer callback, cleanup actions or free functions.

With the fix, three matching unbind runs completed without KASAN, BUG, WARNING, Oops or panic. Instrumentation confirmed that timer retirement completed before the first timer backing allocation was released.

Split timer retirement from the power cleanup and register its devres action after the timer backing data and IRQ actions are installed. This preserves the early power rollback action while ensuring the timer is retired before its backing data is released. Use timershutdownsync() because the callback can rearm itself.

Affected Software

1 affected component
Linux Linux kernel pwm-fan driver

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Use timer_shutdown_sync() to stop and retire the RPM timer before freeing the devm-managed tach data, including the ctx->tachs and ctx->pulses_per_revolution arrays.

Event History

Oct 6, 2026
CVE Published
via MITRE·08:44 AM
Data Sourced
via MITRE·08:44 AM
Description
Data Sourced
via NVD·09:18 AM
Description

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203