CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's handling of negative current limits in the ltc4282 driver, where negative values passed to the ltc4282_write_curr() function are improperly cast to unsigned long, resulting in potential overflow and unpredictable behavior. This can lead to erroneous voltage settings being applied, which may compromise system stability or safety. Users and administrators of systems utilizing the Linux kernel with the ltc4282 driver should prioritize patching this vulnerability to mitigate risks associated with incorrect hardware monitoring and control.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: hwmon: (ltc4282) Clamp negative current limits When a negative value is passed to ltc4282_write_curr(), the signed long val is cast directly to u64: drivers/hwmon/ltc4282.c:ltc4282_write_curr() { /* need to pass it in millivolt */ u32 in = DIV_ROUND_CLOSEST_ULL((u64)val * st->rsense, DECA * MICRO); ... } This cast converts negative inputs into large positive values. The subsequent division result overflows the u32 in variable, truncating to a pseudo-random positive value. When this is passed to ltc4282_write_voltage_byte(), it is clamped to the maximum limit instead of zero. Clamp val to 0 and to the maximum supported upper limit before the cast and assign the result to a 64-bit temporary variable before the division to avoid the underflow and an also possible overflow.