bnxt_en: Fix call to hardware monitoring event handler
Summary
| CVE | CVE-2026-90101 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-17 17:17:01 UTC |
| Updated | 2026-09-17 17:17:01 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
bnxt_en: Fix call to hardware monitoring event handler
The first parameter of hwmon_notify_event() is supposed to be the hardware
monitoring device. The bnxt driver calls it with the platform device as
first parameter instead. This API break results in undefined behavior and
may result in a crash.
Pass the hardware monitoring device as parameter instead to fix the
problem. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected a19b4801457b0806c0153dc344f548c6f8615896 e3cad8389a72b8a309b5689c1683310126b0d7da git |
Not specified |
| CNA |
Linux |
Linux |
affected a19b4801457b0806c0153dc344f548c6f8615896 001ff5d8e68aacd91768b824b930dd7e68db6688 git |
Not specified |
| CNA |
Linux |
Linux |
affected a19b4801457b0806c0153dc344f548c6f8615896 b17907ef665bc76a495a8f909f74656d3f32b7a2 git |
Not specified |
| CNA |
Linux |
Linux |
affected a19b4801457b0806c0153dc344f548c6f8615896 622d698df4239fef3e0eb51fe59f4198f957f28a git |
Not specified |
| CNA |
Linux |
Linux |
affected 6.7 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.7 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.110 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.52 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2.6 7.2.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.3-rc1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/001ff5d8e68aacd91768b824b930dd7e68db6688 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/b17907ef665bc76a495a8f909f74656d3f32b7a2 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/622d698df4239fef3e0eb51fe59f4198f957f28a |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/e3cad8389a72b8a309b5689c1683310126b0d7da |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.