CVE-2026-98198: hwmon: (pwm-fan) Stop RPM timer before freeing tach data
In the Linux kernel, the following vulnerability has been resolved:
hwmon: (pwm-fan) Stop RPM timer before freeing tach data
sampletimer() rearms the RPM timer and accesses the devm-managed ctx->tachs and ctx->pulsesperrevolution arrays. The cleanup action which stops the timer is registered before those arrays are allocated.
Since devres releases entries in reverse order, driver detach can free the arrays before pwmfancleanup() shuts down the timer. A timer expiry in that window accesses the freed tach data.
With a KASAN kernel, a test-only kprobe delayed entry to pwmfancleanup() while normal sysfs unbind ran. Each of three runs reported three four-byte reads and two four-byte writes in sampletimer() after its backing devm allocations had been freed. The helper did not invoke the timer callback, cleanup actions or free functions.
With the fix, three matching unbind runs completed without KASAN, BUG, WARNING, Oops or panic. Instrumentation confirmed that timer retirement completed before the first timer backing allocation was released.
Split timer retirement from the power cleanup and register its devres action after the timer backing data and IRQ actions are installed. This preserves the early power rollback action while ensuring the timer is retired before its backing data is released. Use timershutdownsync() because the callback can rearm itself.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Use timer_shutdown_sync() to stop and retire the RPM timer before freeing the devm-managed tach data, including the ctx->tachs and ctx->pulses_per_revolution arrays.