Executive brief
The Linux kernel's Renesas thermal driver contains a logic error in device initialization that can cause a system crash. The driver attempts to enable a thermal zone device before verifying that registration succeeded, leading to a crash if registration fails. This affects system stability on devices using the rcar thermal management subsystem.
Technical details
The vulnerability is a use-after-error in the rcar_thermal_probe() function within the Linux kernel's thermal driver. The code calls thermal_zone_device_enable() on the return value of thermal_zone_device_register_with_trips() before checking whether registration succeeded; if registration fails, the function returns an error pointer (ERR_PTR), and dereferencing it causes a crash. The fix reorders the code to check for errors immediately after registration and only calls thermal_zone_device_enable() or thermal_add_hwmon_sysfs() after confirming success. The vulnerability requires the thermal zone device registration to fail (a condition unlikely during normal operation but possible under memory pressure or misconfiguration). A fix is available in the Linux kernel stable tree.
Affected products
- Linux Linux kernel Affected versions prior to fix (no specific range provided; patch available in stable branches)
Timeline
- 2026-09-17: disclosed
- 2026-06-26: patched: Upstream fix committed; backported to stable branches