Denial of Service Vulnerability in Linux Kernel's ADT7470 Temperature Sensor Management
CVE-2026-74547
What is CVE-2026-74547?
In the Linux kernel, a vulnerability in the ADT7470 temperature sensor driver allows for a denial of service condition. When the userspace sets the 'auto_update_interval' to 0, a background thread can enter a busy-loop, overloading the CPU and flooding the I2C bus. This is exacerbated when 'num_temp_sensors' is also set to 0, leading to unbounded operations that disrupt system stability. The vulnerability is addressed by adjusting the minimum update interval to ensure a controlled sleep period, thereby preventing excessive bus transactions.
Affected Version(s)
Linux 89fac11cb3e7c5860c425dba14845c09ccede39d < 1a42bd72a66205e439db1d1142442b62d393408a
Linux 89fac11cb3e7c5860c425dba14845c09ccede39d < 38e6b5ce5794ff09442231cc171c2be5e900bab3
Linux 89fac11cb3e7c5860c425dba14845c09ccede39d < 82d65f7ef11edcea0228745440b8b4b1f222c34c