Description
In the Linux kernel, the following vulnerability has been resolved:

thermal/drivers/rcar: Fix error checking in probe()

This code accidentally calls thermal_zone_device_enable() before checking
whether thermal_zone_device_register_with_trips() failed. Move the call
until later to avoid an error pointer dereference of "priv->zone".

The driver works differently depending on if we are using OF thermal or
not. We use thermal_add_hwmon_sysfs() if we are using OF thermal and
call thermal_zone_device_enable() if not. We can share same error check
for if either of these fail.

Moving the thermal_zone_device_enable() call is a bit cleaner as well.
The original code used a three step process to cleanup:
1. Call thermal_zone_device_unregister() to cleanup.
2. Set priv->zone to an error pointer to preserve the error code.
3. Set priv->zone to NULL to avoid a second call to
thermal_zone_device_unregister() in the rcar_thermal_remove()
function.

Now we can just do a direct goto error_unregister and rcar_thermal_remove()
handles the cleanup properly.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel pointer dereference leading to crash or corruption
Action: Update kernel
AI Analysis

Impact

The rcar thermal driver calls thermal_zone_device_enable() before verifying that thermal_zone_device_register_with_trips() succeeded. If registration fails, the priv->zone pointer is set to an error value; invoking enable on this value results in a dereference of a potentially invalid pointer, which can trigger a kernel oops, crash, or data corruption. This flaw is a classic error‑encoded pointer dereference and can destabilize the kernel when the driver is loaded.

Affected Systems

All Linux kernel builds that incorporate the rcar thermal driver source before the patch are vulnerable. The vendor is Linux and the affected product is the Linux kernel itself; no specific version range is provided, so any unpatched build may be at risk.

Risk and Exploitability

Based on the description, it is inferred that the likely attack vector is local privileged access that forces a registration failure, leading to an error pointer dereference. The EPSS score is <1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation in the wild. Exploitation would likely require local privileged access to manipulate the driver’s initialization path or force a registration failure. If successful, the flaw could cause a kernel crash or data corruption, affecting system availability and integrity. The attack vector is local, potentially through device firmware or privileged software interacting with the thermal subsystem.

Generated by OpenCVE AI on September 19, 2026 at 09:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest stable Linux kernel that includes the rcar thermal driver fix.
  • If a kernel upgrade is not immediately possible, disable the rcar thermal driver until the patch is applied.
  • Restrict privileged users from interacting with the thermal subsystem until the update is applied.
  • Monitor kernel logs for thermal zone registration failures or kernel PANICs.

Generated by OpenCVE AI on September 19, 2026 at 09:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476
CWE-865

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: thermal/drivers/rcar: Fix error checking in probe() This code accidentally calls thermal_zone_device_enable() before checking whether thermal_zone_device_register_with_trips() failed. Move the call until later to avoid an error pointer dereference of "priv->zone". The driver works differently depending on if we are using OF thermal or not. We use thermal_add_hwmon_sysfs() if we are using OF thermal and call thermal_zone_device_enable() if not. We can share same error check for if either of these fail. Moving the thermal_zone_device_enable() call is a bit cleaner as well. The original code used a three step process to cleanup: 1. Call thermal_zone_device_unregister() to cleanup. 2. Set priv->zone to an error pointer to preserve the error code. 3. Set priv->zone to NULL to avoid a second call to thermal_zone_device_unregister() in the rcar_thermal_remove() function. Now we can just do a direct goto error_unregister and rcar_thermal_remove() handles the cleanup properly.
Title thermal/drivers/rcar: Fix error checking in probe()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:41.430Z

Reserved: 2026-09-17T16:02:15.088Z

Link: CVE-2026-93142

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:09.267

Modified: 2026-09-17T17:18:09.267

Link: CVE-2026-93142

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T16:45:16Z

Weaknesses