CVE-2026-92504

Linux · Kernel

A resource cleanup vulnerability in the Linux kernel Intel thermal driver allows for potential memory management issues during probe failures.

Executive summary

A memory management flaw in the Linux kernel Intel thermal driver could allow a local attacker with low privileges to trigger system instability or escalate impact.

Vulnerability

The vulnerability exists within the intel/int3400 thermal driver where failures during the probe process fail to properly clean up ODVP sysfs files and associated memory. This requires a locally authenticated user to trigger the specific failure condition during driver initialization.

Business impact

While the CVSS score is 7.0, the actual exploitability is constrained by the requirement for local access and specific hardware/driver initialization failure conditions. If successfully triggered, this could lead to memory corruption or kernel-level instability, potentially resulting in unauthorized system reboots or denial of service, which impacts overall system availability and reliability.

Remediation

Immediate Action: Update the Linux kernel to the corrected versions (5.10.270, 5.15.221, 6.1.188, 6.6.157, or later) as provided by your distribution maintainer.

Proactive Monitoring: Monitor system logs for kernel panic events or unexpected hardware driver initialization failures that may indicate an attempt to trigger this vulnerability.

Compensating Controls: Restrict access to the system to authorized personnel only, as this vulnerability requires local, authenticated access to the target host to be effective.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability represents a moderate risk to system stability for environments utilizing affected Linux kernel versions. IT administrators should prioritize patching during the next standard maintenance cycle, focusing on systems where the Intel thermal driver is actively utilized. Ensure that all kernel updates are tested in a non-production environment before deployment to avoid potential regressions.

More Linux CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 7.0 (3.1)
  4. Analyst report written

Sources