Executive brief
A resource leak vulnerability was identified in the Linux kernel's hardware monitoring driver for the NCT7363 chip, which manages fan speeds and PWM signals. This flaw could allow a local user to cause a gradual depletion of system resources, potentially leading to system instability or a denial-of-service condition over time. The issue has been resolved in recent kernel updates.
Technical details
A memory management flaw exists in the nct7363_present_pwm_fanin function within the drivers/hwmon/nct7363.c component of the Linux kernel. The function calls of_parse_phandle_with_args() but fails to subsequently call of_node_put() to release the reference to the device node. This results in a reference count leak (CWE-401). A local attacker with low privileges could potentially exploit this to exhaust kernel memory or resources, leading to a denial-of-service. Patches have been merged into stable kernel branches to ensure the reference is properly released.
Affected products
- Linux Linux Kernel 6.13 to 6.18.16, 6.19 to 6.19.6
Timeline
- 2026-01-15: other: Patch authored
- 2026-05-06: disclosed: CVE published
- 2026-05-06: advisory