Type Confusion Vulnerability in Linux Kernel hwmon Driver by The Linux Foundation
CVE-2026-74711

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
22 August 2026

What is CVE-2026-74711?

A type confusion vulnerability exists in the hwmon driver of the Linux kernel, specifically within the notification logic of the PMBus interface. The vulnerability arises due to improper casting of device attributes, leading to potential slab-out-of-bounds memory reads. When attributes from the PMBus data group are not correctly identified as sensor_device_attribute, this may allow out-of-bounds access. The risk includes the possibility of retrieving nonsensical data or triggering unwanted alerts due to overlapping memory fields on little-endian systems. This issue can undermine system integrity and may facilitate exploitation in certain conditions, warranting swift attention and rectification.

Affected Version(s)

Linux f469bde9afd136598a0c4edc054296e6046f90ee < 821f6416e69782fa662aff94b5ea52c943042790

Linux f469bde9afd136598a0c4edc054296e6046f90ee < 0b121de89a99c54bcf516999b04e8531c84f08d5

Linux f469bde9afd136598a0c4edc054296e6046f90ee < 59bd68ab05a8f9c9a60b6ec44682084184803ff4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.