Description
In the Linux kernel, the following vulnerability has been resolved:

thermal: intel: int3400: clean up ODVP on probe failures

evaluate_odvp() creates per-ODVP sysfs files before the thermal zone
and later probe resources are registered. The current unwind path only
calls cleanup_odvp() from the late sysfs failure path, so failures after
evaluate_odvp() but before that label, including
thermal_tripless_zone_device_register() failures, leave the ODVP files
and storage behind.

Move the ODVP cleanup to the common ART/TRT unwind path so every failure
after evaluate_odvp() releases the ODVP state. Also clear the cached
ODVP pointers in cleanup_odvp(), because evaluate_odvp() can already call
it for partial setup failures while probe continues.
Published: 2026-09-17
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Resource Leak
Action: Patch
AI Analysis

Impact

In the Linux kernel, the Intel int3400 thermal driver does not properly remove ODVP (overdrive temperature package) sysfs files and associated memory when a probe fails after evaluate_odvp() but before the cleanup_odvp() routine is executed. The existing unwind path only deletes these objects in a late sysfs failure point, leaving orphaned entries and cached pointers. This creates a resource‑leak scenario that can accumulate over time, potentially exhausting kernel resources and causing system instability. The flaw arises from missing cleanup of system state after a partial failure.

Affected Systems

The vulnerability affects any Linux system that loads the Intel int3400 thermal driver. Specific kernel versions are not listed in the advisory, so all kernels that register this driver and experience probe failures after evaluate_odvp() could be impacted. Administrators should verify whether their installed kernel includes the int3400 driver and whether a newer kernel release contains the patch.

Risk and Exploitability

The CVSS score of 7 indicates a moderately high severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the vulnerability can be triggered by a local or privileged user during boot or module loading when a probe failure occurs. The impact is limited to a resource leak and potential instability, with no direct code‑execution pathway or known remote exploitation.

Generated by OpenCVE AI on September 20, 2026 at 00:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest Linux kernel version that includes the int3400 ODVP cleanup patch
  • If an upgrade is not possible, disable or blacklist the intel,int3400 module using modprobe.d or kernel boot parameters to prevent the vulnerable probe path from executing
  • After boot, inspect /sys/class/thermal for any orphaned ODVP entries and remove them manually if present

Generated by OpenCVE AI on September 20, 2026 at 00:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-399

Sat, 19 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-776

Sat, 19 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-776

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: thermal: intel: int3400: clean up ODVP on probe failures evaluate_odvp() creates per-ODVP sysfs files before the thermal zone and later probe resources are registered. The current unwind path only calls cleanup_odvp() from the late sysfs failure path, so failures after evaluate_odvp() but before that label, including thermal_tripless_zone_device_register() failures, leave the ODVP files and storage behind. Move the ODVP cleanup to the common ART/TRT unwind path so every failure after evaluate_odvp() releases the ODVP state. Also clear the cached ODVP pointers in cleanup_odvp(), because evaluate_odvp() can already call it for partial setup failures while probe continues.
Title thermal: intel: int3400: clean up ODVP on probe failures
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:55:29.519Z

Reserved: 2026-09-16T12:21:13.872Z

Link: CVE-2026-92504

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:52.937

Modified: 2026-09-18T18:18:13.180

Link: CVE-2026-92504

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T00:30:16Z

Weaknesses