CVE-2026-90101

medium

Description

In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Fix call to hardware monitoring event handler The first parameter of hwmon_notify_event() is supposed to be the hardware monitoring device. The bnxt driver calls it with the platform device as first parameter instead. This API break results in undefined behavior and may result in a crash. Pass the hardware monitoring device as parameter instead to fix the problem.

References

https://git.kernel.org/stable/c/e3cad8389a72b8a309b5689c1683310126b0d7da

https://git.kernel.org/stable/c/b17907ef665bc76a495a8f909f74656d3f32b7a2

https://git.kernel.org/stable/c/622d698df4239fef3e0eb51fe59f4198f957f28a

https://git.kernel.org/stable/c/001ff5d8e68aacd91768b824b930dd7e68db6688

Details

Source: Mitre, NVD

Published: 2026-09-17

Updated: 2026-09-17

Risk Information

CVSS v2

Base Score: 6.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.002