Vulnerability in the Linux Kernel Affecting Current Measurement Functionality
CVE-2026-74685
What is CVE-2026-74685?
A vulnerability in the Linux kernel arises from improper input validation in the function responsible for writing current values to the LTC4282 hardware monitor. Specifically, when negative values are erroneously passed to this function, they are cast directly to an unsigned long, resulting in an overflow. This issue can lead to unintended large positive values which affect subsequent calculations, potentially compromising hardware monitoring accuracy. To mitigate this vulnerability, it is imperative to clamp values being passed, ensuring they stay within the supported limits before any further processing.
Affected Version(s)
Linux cbc29538dbf7d7400f1ffc5dd5713e6a551463a0 < 60e06c4dba696173982393252a40ceb7dd2eec18
Linux cbc29538dbf7d7400f1ffc5dd5713e6a551463a0
Linux cbc29538dbf7d7400f1ffc5dd5713e6a551463a0 < 046e56b53c09375ef39903514496aa5508db9729