CVE-2026-74685
Last modified
CVE-2026-74685 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: hwmon: (ltc4282) Clamp negative current limits When a negative value is passed to ltc4282_write_curr(), the signed long val is cast directly to u64: drivers/hwmon/ltc4282.c:ltc4282_write_curr() { /* need to pass it in millivolt */ u32 in = DIV_ROUND_CLOSEST_ULL((u64)val * st->rsense, DECA * MICRO); ... } This cast converts negative inputs into large positive values. The subsequent division result overflows the u32 in variable, truncating to a pseudo-random positive value.
Description
In the Linux kernel, the following vulnerability has been resolved: hwmon: (ltc4282) Clamp negative current limits When a negative value is passed to ltc4282_write_curr(), the signed long val is cast directly to u64: drivers/hwmon/ltc4282.c:ltc4282_write_curr() { /* need to pass it in millivolt */ u32 in = DIV_ROUND_CLOSEST_ULL((u64)val * st->rsense, DECA * MICRO); ... } This cast converts negative inputs into large positive values. The subsequent division result overflows the u32 in variable, truncating to a pseudo-random positive value. When this is passed to ltc4282_write_voltage_byte(), it is clamped to the maximum limit instead of zero. Clamp val to 0 and to the maximum supported upper limit before the cast and assign the result to a 64-bit temporary variable before the division to avoid the underflow and an also possible overflow.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= cbc29538dbf7d7400f1ffc5dd5713e6a551463a0, < 60e06c4dba696173982393252a40ceb7dd2eec18; >= cbc29538dbf7d7400f1ffc5dd5713e6a551463a0, < de58b90a4d1417c15b693eb04c0ce6bc925d84c6; >= cbc29538dbf7d7400f1ffc5dd5713e6a551463a0, < 046e56b53c09375ef39903514496aa5508db9729; >= cbc29538dbf7d7400f1ffc5dd5713e6a551463a0, < e253dd5f9f6d875a317895bf43ec9534ed7523cb |
| Linux | Linux | 6.9 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-74685?
How severe is CVE-2026-74685?
How do I fix CVE-2026-74685?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-7468A security vulnerability has been detected in 1024-lab smart…7.3
- CVE-2026-74680In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74681In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74682In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74683In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74684In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74686In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74687In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74688In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74689In the Linux kernel, the following vulnerability has been re…
- CVE-2026-7469A vulnerability was detected in Tenda 4G300 US_4G300V1.0Mt_V…6.3
- CVE-2026-74690In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-74685?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
