SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-74685

UNKNOWN · CVSS N/A EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-08-22 · Last synced 2026-09-20

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's handling of negative current limits in the ltc4282 driver, where negative values passed to the ltc4282_write_curr() function are improperly cast to unsigned long, resulting in potential overflow and unpredictable behavior. This can lead to erroneous voltage settings being applied, which may compromise system stability or safety. Users and administrators of systems utilizing the Linux kernel with the ltc4282 driver should prioritize patching this vulnerability to mitigate risks associated with incorrect hardware monitoring and control.

CVE
CVE-2026-74685
Severity
UNKNOWN
CVSS
N/A
EPSS
0.17%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: hwmon: (ltc4282) Clamp negative current limits When a negative value is passed to ltc4282_write_curr(), the signed long val is cast directly to u64: drivers/hwmon/ltc4282.c:ltc4282_write_curr() { /* need to pass it in millivolt */ u32 in = DIV_ROUND_CLOSEST_ULL((u64)val * st->rsense, DECA * MICRO); ... } This cast converts negative inputs into large positive values. The subsequent division result overflows the u32 in variable, truncating to a pseudo-random positive value. When this is passed to ltc4282_write_voltage_byte(), it is clamped to the maximum limit instead of zero. Clamp val to 0 and to the maximum supported upper limit before the cast and assign the result to a 64-bit temporary variable before the division to avoid the underflow and an also possible overflow.