CVE-2026-97968
CVE CVE-2026-97968EUVD EUVD-2026-86822Published 2026-09-25T10:23:09.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: hwmon: (corsair-cpro) Create debugfs entries after hwmon registration ccp_debugfs_init() registers debugfs files whose private data is the devm allocated ccp. It runs before hwmon_device_register_with_info(), so when that registration fails, ccp_probe() returns with the files still in place. The HID core then frees ccp, and ccp_remove() is not called for a failed probe, so nothing removes them later either. Reading one of the files dereferences the freed pointer. Create the debugfs entries only after the hwmon device has been registered, so no failing path can leave them behind. The two version queries stay where they are. They send USB commands without holding ccp->mutex, which is only safe as long as nothing else can call send_usb_cmd(); once the hwmon device is registered its callbacks can do so concurrently. Only the debugfs creation moves, and it is told which queries succeeded.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 5997eb60f896830126bc1783465b678b110e2fdd <a58a966a440071bb877ef62535d1016952f83101; 5997eb60f896830126bc1783465b678b110e2fdd <508baf1713f32f287bfb4f85d759403ec8ba35a3; 5997eb60f896830126bc1783465b678b110e2fdd <fdfe17cb865715aad30328678344eb79889207ab; patch: 7.2.7; 5997eb60f896830126bc1783465b678b110e2fdd <6c5d333216a937044acd3336e9ec7e30ff2eaee4; 6.11; patch: 0; patch: 7.3-rc3; patch: 6.12.111; patch: 6.18.53
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.