SB20260828111 - Deadlock in Linux kernel hwmon occ driver
Published: August 28, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Deadlock (CVE-ID: CVE-2026-80660)
CWE-ID: CWE-833 - Deadlock
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a deadlock in the occ hwmon sysfs device handling in drivers/hwmon/occ/common.c when unregistering sysfs-backed devices during concurrent sysfs callbacks. A local user can trigger concurrent sysfs access and device shutdown activity to cause a denial of service.
The issue involves circular locking between the OCC mutex and sysfs callback draining during device deactivation or shutdown.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/2092952f22a7da98e76e84139ae202b1fc7ba899
- https://git.kernel.org/stable/c/2a4c80ff3571498ec6a916273304b6650026b1b0
- https://git.kernel.org/stable/c/7ee43ec8e6774774abbe9dc3027225e01bc964a5
- https://git.kernel.org/stable/c/e31408734332b8cc611342cdaaab6ba492180156
- https://git.kernel.org/stable/c/e7fd81e9fb1fe476d2131fec66c1138457810ed4
- https://git.kernel.org/stable/c/f0aad157576da199c146c1bb266442befa7912ca