0.0
NA
CVE-2026-74604
Revert "thermal/drivers/hwmon: Cleanup coding style a bit"
Description

In the Linux kernel, the following vulnerability has been resolved: Revert "thermal/drivers/hwmon: Cleanup coding style a bit" Revert commit 030a48b0f6ce ("thermal/drivers/hwmon: Cleanup coding style a bit") that introduced a use-after-free into the error path of thermal_add_hwmon_sysfs() by removing a valid check from it.

INFO

Published Date :

Aug. 22, 2026, 4:16 p.m.

Last Modified :

Aug. 22, 2026, 4:16 p.m.

Remotely Exploit :

No

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-74604 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Linux linux_kernel
Solution
Revert commit introducing use-after-free in error path.
  • Revert the specified commit.
  • Apply the original commit without the faulty changes.
  • Test the thermal error path functionality thoroughly.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-74604 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-74604 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-74604 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-74604 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Aug. 22, 2026

    Action Type Old Value New Value
    Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '1da177e4c3f41524e886b7f1b8a0c1fc7321cac2', 'lessThan': '2434f4765da8ccd7ef31be88b86f1bfa2e95be11', 'versionType': 'git'}, {'status': 'affected', 'version': '1da177e4c3f41524e886b7f1b8a0c1fc7321cac2', 'lessThan': 'b4c01ae6dd56d9dfd96bd1b29c28afa8fa06b366', 'versionType': 'git'}, {'status': 'affected', 'version': '1da177e4c3f41524e886b7f1b8a0c1fc7321cac2', 'lessThan': '999e573212d5f1debf073c68be35e55bbfad12fc', 'versionType': 'git'}, {'status': 'affected', 'version': '1da177e4c3f41524e886b7f1b8a0c1fc7321cac2', 'lessThan': '6a48ee9a5bda0f8ee501f9bef159fb9f39ff519a', 'versionType': 'git'}, {'status': 'affected', 'version': '1da177e4c3f41524e886b7f1b8a0c1fc7321cac2', 'lessThan': '8d34019d1413629a434a7e8d9f91c76d256196a0', 'versionType': 'git'}, {'status': 'affected', 'version': '1da177e4c3f41524e886b7f1b8a0c1fc7321cac2', 'lessThan': '6b446d335ba16e93a266dd77adf1ba51abc82df4', 'versionType': 'git'}, {'status': 'affected', 'version': '1da177e4c3f41524e886b7f1b8a0c1fc7321cac2', 'lessThan': 'ff8da20b6f47c48d46e47f93f7a59e2d56ee9107', 'versionType': 'git'}, {'status': 'affected', 'version': '0', 'lessThan': '5.15.216', 'versionType': 'semver'}, {'status': 'affected', 'version': '0', 'lessThan': '6.1.183', 'versionType': 'semver'}, {'status': 'affected', 'version': '0', 'lessThan': '6.6.152', 'versionType': 'semver'}, {'status': 'affected', 'version': '0', 'lessThan': '6.12.104', 'versionType': 'semver'}, {'status': 'affected', 'version': '0', 'lessThan': '6.18.45', 'versionType': 'semver'}, {'status': 'affected', 'version': '0', 'lessThan': '7.1.9', 'versionType': 'semver'}], 'programFiles': ['drivers/thermal/thermal_hwmon.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'unaffected', 'version': '5.15.216', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.183', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.152', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.104', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.45', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.9', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/thermal/thermal_hwmon.c'], 'defaultStatus': 'affected'}]
    Added Description In the Linux kernel, the following vulnerability has been resolved: Revert "thermal/drivers/hwmon: Cleanup coding style a bit" Revert commit 030a48b0f6ce ("thermal/drivers/hwmon: Cleanup coding style a bit") that introduced a use-after-free into the error path of thermal_add_hwmon_sysfs() by removing a valid check from it.
    Added Reference https://git.kernel.org/stable/c/2434f4765da8ccd7ef31be88b86f1bfa2e95be11
    Added Reference https://git.kernel.org/stable/c/6a48ee9a5bda0f8ee501f9bef159fb9f39ff519a
    Added Reference https://git.kernel.org/stable/c/6b446d335ba16e93a266dd77adf1ba51abc82df4
    Added Reference https://git.kernel.org/stable/c/8d34019d1413629a434a7e8d9f91c76d256196a0
    Added Reference https://git.kernel.org/stable/c/999e573212d5f1debf073c68be35e55bbfad12fc
    Added Reference https://git.kernel.org/stable/c/b4c01ae6dd56d9dfd96bd1b29c28afa8fa06b366
    Added Reference https://git.kernel.org/stable/c/ff8da20b6f47c48d46e47f93f7a59e2d56ee9107
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.