7.8
CVE-2026-74549
- EPSS 0.13%
- Veröffentlicht 15.08.2026 12:27:56
- Zuletzt bearbeitet 19.08.2026 17:21:09
- CVE-Watchlists
- Unerledigt
hwmon: (nct6775-core) Prevent access to unsupported weight registers
In the Linux kernel, the following vulnerability has been resolved: hwmon: (nct6775-core) Prevent access to unsupported weight registers Sashiko reports: During initialization of the nct6116 chip, the driver sets data->pwm_num to 5. However, it assigns several NCT6106 register arrays (such as NCT6106_REG_WEIGHT_DUTY_STEP, NCT6106_REG_WEIGHT_TEMP_SEL, and NCT6106_REG_WEIGHT_TEMP_*) to data->REG_PWM and data->REG_WEIGHT_TEMP. These arrays only contain 3 elements. In nct6775_update_pwm(), the driver iterates up to data->pwm_num. If data->has_pwm has bits 3 or 4 set (which is structurally possible for nct6116), the loop attempts to read elements at index 3 and 4 from these 3-element arrays. This results in a global out-of-bounds read, which can be caught by KASAN. Furthermore, the driver uses these garbage out-of-bounds values as hardware register addresses for subsequent read and write operations. This leads to invalid hardware register access, potentially causing hardware misconfiguration or system crashes. The underlying problem is that the chip does support up to five fan control channels, but only the first three support weight control. Fix the problem by extending the affected weight register arrays with zeroed fields. The driver uses zeroed register addresses to determine if a register is supported or not, and skips accesses for unsupported registers.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
29c7cb485b321c024dedc168bcbb04451176b163
Version <
0d11b2a10269ace29832f584d207ff3768f79dc5
Status
affected
Version
29c7cb485b321c024dedc168bcbb04451176b163
Version <
4a77f1d72c6db04cbbfab0250292ac71fdea5f0a
Status
affected
Version
29c7cb485b321c024dedc168bcbb04451176b163
Version <
513d847f7a95bbdbeaaf55fb942c38992587734f
Status
affected
Version
29c7cb485b321c024dedc168bcbb04451176b163
Version <
25b528816f5d83be5236dc182692369e8c9402b0
Status
affected
Version
29c7cb485b321c024dedc168bcbb04451176b163
Version <
689082a4cb166a7ae9729f7b12339e69fdad6c52
Status
affected
Version
29c7cb485b321c024dedc168bcbb04451176b163
Version <
1b722740ac5c2b2070f9ba922f4e0f227faf0246
Status
affected
Version
29c7cb485b321c024dedc168bcbb04451176b163
Version <
4ad2972ef0e1bd1018ad7a72661a4636ed7daecc
Status
affected
Version
29c7cb485b321c024dedc168bcbb04451176b163
Version <
d0b704e569ac3b8416d8e02270cdc9bf830ed395
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
5.4
Status
affected
Version
0
Version <
5.4
Status
unaffected
Version <=
5.10.*
Version
5.10.265
Status
unaffected
Version <=
5.15.*
Version
5.15.216
Status
unaffected
Version <=
6.1.*
Version
6.1.183
Status
unaffected
Version <=
6.6.*
Version
6.6.151
Status
unaffected
Version <=
6.12.*
Version
6.12.103
Status
unaffected
Version <=
6.18.*
Version
6.18.44
Status
unaffected
Version <=
7.1.*
Version
7.1.8
Status
unaffected
Version <=
*
Version
7.2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.13% | 0.031 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/25b528816f5d83be5236dc182692369e8c9402b0
https://git.kernel.org/stable/c/689082a4cb166a7ae9729f7b12339e69fdad6c52
https://git.kernel.org/stable/c/1b722740ac5c2b2070f9ba922f4e0f227faf0246
https://git.kernel.org/stable/c/4ad2972ef0e1bd1018ad7a72661a4636ed7daecc
https://git.kernel.org/stable/c/d0b704e569ac3b8416d8e02270cdc9bf830ed395
https://git.kernel.org/stable/c/0d11b2a10269ace29832f584d207ff3768f79dc5
https://git.kernel.org/stable/c/4a77f1d72c6db04cbbfab0250292ac71fdea5f0a
https://git.kernel.org/stable/c/513d847f7a95bbdbeaaf55fb942c38992587734f