hwmon: (ltc4282) Clamp negative current limits
Summary
| CVE | CVE-2026-74685 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-22 16:16:42 UTC |
| Updated | 2026-08-22 16:16:42 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
hwmon: (ltc4282) Clamp negative current limits
When a negative value is passed to ltc4282_write_curr(), the signed long
val is cast directly to u64:
drivers/hwmon/ltc4282.c:ltc4282_write_curr() {
/* need to pass it in millivolt */
u32 in = DIV_ROUND_CLOSEST_ULL((u64)val * st->rsense, DECA * MICRO);
...
}
This cast converts negative inputs into large positive values. The
subsequent division result overflows the u32 in variable, truncating
to a pseudo-random positive value. When this is passed to
ltc4282_write_voltage_byte(), it is clamped to the maximum limit instead
of zero.
Clamp val to 0 and to the maximum supported upper limit before the cast
and assign the result to a 64-bit temporary variable before the division
to avoid the underflow and an also possible overflow. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected cbc29538dbf7d7400f1ffc5dd5713e6a551463a0 60e06c4dba696173982393252a40ceb7dd2eec18 git |
Not specified |
| CNA |
Linux |
Linux |
affected cbc29538dbf7d7400f1ffc5dd5713e6a551463a0 de58b90a4d1417c15b693eb04c0ce6bc925d84c6 git |
Not specified |
| CNA |
Linux |
Linux |
affected cbc29538dbf7d7400f1ffc5dd5713e6a551463a0 046e56b53c09375ef39903514496aa5508db9729 git |
Not specified |
| CNA |
Linux |
Linux |
affected cbc29538dbf7d7400f1ffc5dd5713e6a551463a0 e253dd5f9f6d875a317895bf43ec9534ed7523cb git |
Not specified |
| CNA |
Linux |
Linux |
affected 6.9 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.9 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.104 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.45 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1.9 7.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/60e06c4dba696173982393252a40ceb7dd2eec18 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/de58b90a4d1417c15b693eb04c0ce6bc925d84c6 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/e253dd5f9f6d875a317895bf43ec9534ed7523cb |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/046e56b53c09375ef39903514496aa5508db9729 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.