CVE-2026-74685
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
hwmon: (ltc4282) Clamp negative current limits
When a negative value is passed to ltc4282_write_curr(), the signed long val is cast directly to u64:
drivers/hwmon/ltc4282.c:ltc4282_write_curr() { /* need to pass it in millivolt */ u32 in = DIV_ROUND_CLOSEST_ULL((u64)val * st->rsense, DECA * MICRO); … }
This cast converts negative inputs into large positive values. The subsequent division result overflows the u32 in variable, truncating to a pseudo-random positive value. When this is passed to ltc4282_write_voltage_byte(), it is clamped to the maximum limit instead of zero.
Clamp val to 0 and to the maximum supported upper limit before the cast and assign the result to a 64-bit temporary variable before the division to avoid the underflow and an also possible overflow.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | cbc29538dbf7d7400f1ffc5dd5713e6a551463a0 < 60e06c4dba696173982393252a40ceb7dd2eec18 | affected |
| Linux | Linux | cbc29538dbf7d7400f1ffc5dd5713e6a551463a0 < de58b90a4d1417c15b693eb04c0ce6bc925d84c6 | affected |
| Linux | Linux | cbc29538dbf7d7400f1ffc5dd5713e6a551463a0 < 046e56b53c09375ef39903514496aa5508db9729 | affected |
| Linux | Linux | cbc29538dbf7d7400f1ffc5dd5713e6a551463a0 < e253dd5f9f6d875a317895bf43ec9534ed7523cb | affected |
| Linux | Linux | 6.9 | affected |
| Linux | Linux | 0 < 6.9 | unaffected |
| Linux | Linux | 6.12.104 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.45 <= 6.18.* | unaffected |
| Linux | Linux | 7.1.9 <= 7.1.* | unaffected |
| Linux | Linux | 7.2 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/60e06c4dba696173982393252a40ceb7dd2eec18
- https://git.kernel.org/stable/c/de58b90a4d1417c15b693eb04c0ce6bc925d84c6
- https://git.kernel.org/stable/c/046e56b53c09375ef39903514496aa5508db9729
- https://git.kernel.org/stable/c/e253dd5f9f6d875a317895bf43ec9534ed7523cb
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.