-

CVE-2026-74685

hwmon: (ltc4282) Clamp negative current limits

In the Linux kernel, the following vulnerability has been resolved:

hwmon: (ltc4282) Clamp negative current limits

When a negative value is passed to ltc4282_write_curr(), the signed long
val is cast directly to u64:

drivers/hwmon/ltc4282.c:ltc4282_write_curr() {
        /* need to pass it in millivolt */
        u32 in = DIV_ROUND_CLOSEST_ULL((u64)val * st->rsense, DECA * MICRO);
        ...
}

This cast converts negative inputs into large positive values. The
subsequent division result overflows the u32 in variable, truncating
to a pseudo-random positive value. When this is passed to
ltc4282_write_voltage_byte(), it is clamped to the maximum limit instead
of zero.

Clamp val to 0 and to the maximum supported upper limit before the cast
and assign the result to a 64-bit temporary variable before the division
to avoid the underflow and an also possible overflow.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version cbc29538dbf7d7400f1ffc5dd5713e6a551463a0
Version < 60e06c4dba696173982393252a40ceb7dd2eec18
Status affected
Version cbc29538dbf7d7400f1ffc5dd5713e6a551463a0
Version < de58b90a4d1417c15b693eb04c0ce6bc925d84c6
Status affected
Version cbc29538dbf7d7400f1ffc5dd5713e6a551463a0
Version < 046e56b53c09375ef39903514496aa5508db9729
Status affected
Version cbc29538dbf7d7400f1ffc5dd5713e6a551463a0
Version < e253dd5f9f6d875a317895bf43ec9534ed7523cb
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 6.9
Status affected
Version 0
Version < 6.9
Status unaffected
Version <= 6.12.*
Version 6.12.104
Status unaffected
Version <= 6.18.*
Version 6.18.45
Status unaffected
Version <= 7.1.*
Version 7.1.9
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.062
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/046e56b53c09375ef39903514496aa5508db9729
https://git.kernel.org/stable/c/60e06c4dba696173982393252a40ceb7dd2eec18
https://git.kernel.org/stable/c/de58b90a4d1417c15b693eb04c0ce6bc925d84c6
https://git.kernel.org/stable/c/e253dd5f9f6d875a317895bf43ec9534ed7523cb