Linux Kernel Coretemp Driver Platform Device Handling Vulnerability

Vulnerability

A vulnerability in the Linux kernel's Coretemp platform driver has been addressed. The driver managed platform devices in a way that could lead to errors, particularly by assuming that device addition would complete synchronously. This could cause null pointer dereferences if certain conditions were met. Additionally, the driver's integration with CPU hotplug events created potential deadlocks and conflicts with other subsystems. The vulnerability has been resolved by simplifying the management of platform devices, tying them directly to the module's lifecycle and handling the associated interfaces more effectively. As a result, while some system paths will no longer display, the functionality for users of the hwmon interfaces remains unchanged.

Impact

The vulnerability could lead to null pointer dereferences and system deadlocks, disrupting normal operations and potentially causing crashes or unresponsive states.

Added: Oct 4, 2025, 4:22 PM
Updated: Oct 4, 2025, 4:22 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
4.0
remediation
7.7
relevance
0.7
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.