๐Ÿ” CVE Alert

CVE-2026-31582

UNKNOWN 0.0

hwmon: (powerz) Fix use-after-free on USB disconnect

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: hwmon: (powerz) Fix use-after-free on USB disconnect After powerz_disconnect() frees the URB and releases the mutex, a subsequent powerz_read() call can acquire the mutex and call powerz_read_data(), which dereferences the freed URB pointer. Fix by: - Setting priv->urb to NULL in powerz_disconnect() so that powerz_read_data() can detect the disconnected state. - Adding a !priv->urb check at the start of powerz_read_data() to return -ENODEV on a disconnected device. - Moving usb_set_intfdata() before hwmon registration so the disconnect handler can always find the priv pointer.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Apr 24, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < c78e1d4e48f23792adaa7c94251e22b0d9700a39 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 9e1b798257f96d2e2a2639830eb71add545ce749 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 7003ae4810ca83f0ddca85b768500e313c4b998c 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 61f2aa23b0ce8d7aa5071ed25a7471e246a4fdd4
Linux / Linux
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/c78e1d4e48f23792adaa7c94251e22b0d9700a39 git.kernel.org: https://git.kernel.org/stable/c/9e1b798257f96d2e2a2639830eb71add545ce749 git.kernel.org: https://git.kernel.org/stable/c/7003ae4810ca83f0ddca85b768500e313c4b998c git.kernel.org: https://git.kernel.org/stable/c/61f2aa23b0ce8d7aa5071ed25a7471e246a4fdd4