CyberRota Analysis
AI-GeneratedA vulnerability in the Linux kernel's hwmon subsystem allows userspace to access sysfs attributes before the driver is fully initialized, leading to a potential NULL pointer dereference. This can result in system instability or crashes when the lm90 driver attempts to report alarms prematurely. Organizations using affected Linux kernel versions should prioritize patching this vulnerability to ensure system reliability and prevent unexpected failures.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: hwmon: (lm90) Only report alarms if driver is ready Userspace can read sysfs attributes before driver registration is complete, immediately after devm_hwmon_device_register_with_info() has been called. At that time, data->hwmon_dev is not yet initialized. This can trigger a NULL pointer access since lm90_update_device() and with it lm90_update_alarms_locked() will be called. This call schedules report_work and lm90_report_alarms(), which passes the still-NULL data->hwmon_dev to hwmon_notify_event() and triggers a NULL pointer dereference. Fix the problem by only scheduling the report and alert workers data->hwmon_dev is set.