Executive brief
The Linux kernel's power management bus (pmbus) hardware monitoring driver contains a type confusion vulnerability in its notification handling code. An attacker with local access could trigger a crash or potentially read sensitive memory by crafting malicious device attributes. This affects systems using pmbus-compatible power supply monitoring hardware.
Technical details
The vulnerability exists in the pmbus_notify() function in drivers/hwmon/pmbus/pmbus_core.c, where the code unconditionally casts all device attributes to struct sensor_device_attribute without first validating their actual type. The attribute group can contain multiple types (pmbus_samples_reg, pmbus_sensor, sensor_device_attribute), but only sensor_device_attribute has the expected index field. When non-matching types are cast, field access either reads out-of-bounds memory (potential slab-out-of-bounds read) or overlaps with unrelated fields, producing garbage values that could cause spurious notification matches. The fix involves using struct sensor_device_attr consistently and setting index to -1 for attributes that never trigger notifications, allowing proper distinction at runtime.
Affected products
- Linux Linux kernel Vulnerable versions unspecified; patch available
Timeline
- 2026-08-22: disclosed