CVE-2026-97582

In the Linux kernel, the following vulnerability has been resolved: hwmon: (gpio-fan) Fix use-after-free in alarm work fan_alarm_irq_handler() queues fan_data->alarm_work, but nothing cancels it. fan_alarm_notify() dereferences fan_data and its hwmon device. On unbind, devres frees the interrupt, which only waits for the handler itself, and then releases the hwmon device and fan_data, so a pending fan_alarm_notify() can run after those frees. Replace INIT_WORK() with devm_work_autocancel(), registered before devm_request_irq(). The devres cleanup then frees the interrupt first, so no new work can be queued, and cancels the work while fan_data and the hwmon device are still alive. This issue was found by an in-house static analysis tool.

Package Linux Kernel
Published 2026-09-25
Last modified 2026-10-03
Patch available
Yes

Affected versions

Linux kernel versions 2.6.37 and later are affected. Fixed in 5.15.222, 6.1.189, 6.6.158, 6.12.111, 6.18.53, 7.2.7, 7.3-rc3 and their respective stable series.

Affected from
≥ 2.6.37
Fixed in
✓ 5.15.222 5.15.x ✓ 6.1.189 6.1.x ✓ 6.6.158 6.6.x ✓ 6.12.111 6.12.x ✓ 6.18.53 6.18.x ✓ 7.2.7 7.2.x ✓ 7.3-rc3

Frequently asked questions

  • What is CVE-2026-97582?

    CVE-2026-97582 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 2.6.37 onward and has been patched in 5.15.222, 6.1.189, 6.6.158 and others. CVE-2026-97582 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.

  • Is there a patch available for CVE-2026-97582?

    Yes. CVE-2026-97582 has been patched. Fixed versions include 5.15.222, 6.1.189, 6.6.158 and others. If you are running Linux kernel 2.6.37 or later up to the fix versions, apply the relevant patch for your kernel branch.

  • Is CVE-2026-97582 actively exploited?

    No. CVE-2026-97582 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.