Bug 2429573 (CVE-2025-71111) - CVE-2025-71111 kernel: hwmon: (w83791d) Convert macros to functions to avoid TOCTOU
Summary: CVE-2025-71111 kernel: hwmon: (w83791d) Convert macros to functions to avoid ...
Keywords:
Status: NEW
Alias: CVE-2025-71111
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-01-14 16:01 UTC by OSIDB Bzimport
Modified: 2026-02-11 18:46 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-01-14 16:01:16 UTC
In the Linux kernel, the following vulnerability has been resolved:

hwmon: (w83791d) Convert macros to functions to avoid TOCTOU

The macro FAN_FROM_REG evaluates its arguments multiple times. When used
in lockless contexts involving shared driver data, this leads to
Time-of-Check to Time-of-Use (TOCTOU) race conditions, potentially
causing divide-by-zero errors.

Convert the macro to a static function. This guarantees that arguments
are evaluated only once (pass-by-value), preventing the race
conditions.

Additionally, in store_fan_div, move the calculation of the minimum
limit inside the update lock. This ensures that the read-modify-write
sequence operates on consistent data.

Adhere to the principle of minimal changes by only converting macros
that evaluate arguments multiple times and are used in lockless
contexts.

Comment 1 Jon Moroney 2026-01-14 21:18:09 UTC Comment hidden (spam)

Note You need to log in before you can comment on or make changes to this bug.