Linux vulnerability

In the Linux kernel, the following vulnerability has been resolved: thermal: core: Fix thermal zone governor cleanup issues If thermal_zone_device_register_with_trips() fails after adding a thermal governor to the thermal zone being registered, the governor is not removed from it as appropriate which may lead to a memory leak. In turn, thermal_zone_device_unregister() calls thermal_set_governor() without acquiring the thermal zone lock beforehand which may race with a governor update via sysfs and may lead to a use-after-free in that case. Address these issues by adding two thermal_set_governor() calls, one to thermal_release() to remove the governor from the given thermal zone, and one to the thermal zone registration error path to cover failures preceding the thermal zone device registration.

Published 27 May 2026Updated 8 Sep 20269 sources
CVSS 5.5

What happened

In the Linux kernel, the following vulnerability has been resolved: thermal: core: Fix thermal zone governor cleanup issues If thermal_zone_device_register_with_trips() fails after adding a thermal governor to the thermal zone being registered, the governor is not removed from it as appropriate which may lead to a memory leak. In turn, thermal_zone_device_unregister() calls thermal_set_governor() without acquiring the thermal zone lock beforehand which may race with a governor update via sysfs and may lead to a use-after-free in that case. Address these issues by adding two thermal_set_governor() calls, one to thermal_release() to remove the governor from the given thermal zone, and one to the thermal zone registration error path to cover failures preceding the thermal zone device registration.

Affected versions

Linux: e33df1d2f3a0141cd79e770f31999ba0dd7ebfa8 through before a172fa18bc370b776ac1510abb0dcb50a7a35fac (git); e33df1d2f3a0141cd79e770f31999ba0dd7ebfa8 through before 8e563d8db50f303171aceb79eec0807e7ba06951 (git); e33df1d2f3a0141cd79e770f31999ba0dd7ebfa8 through before d4eb861adde5ce22e459fbd29366f47bb2167977 (git); e33df1d2f3a0141cd79e770f31999ba0dd7ebfa8 through before 37a430a2d4e66ec8238da6c7f7e48809bf265e13 (git); e33df1d2f3a0141cd79e770f31999ba0dd7ebfa8 through before f412e541d25a3dfaf3d53e012ade6ff03cae8a45 (git); e33df1d2f3a0141cd79e770f31999ba0dd7ebfa8 through before 75f8f3c3e09122270986de9d7aa347d701676761 (git); e33df1d2f3a0141cd79e770f31999ba0dd7ebfa8 through before 64d4ebf91d082034bbc5ae3ba2d7fd800bc02d06 (git); e33df1d2f3a0141cd79e770f31999ba0dd7ebfa8 through before 41ff66baf81c6541f4f985dd7eac4494d03d9440 (git); 4.2; V3.1.6 through before * (custom) Fixed: See vendor advisory.

Why it matters

Review the vendor advisory and exposure of the affected product to determine operational impact.

Detection & mitigation

  • Apply vendor-provided updates or mitigations.
  • Review affected product exposure and access logs.

Public PoC references

No public PoC reference has passed the current publication threshold.