CVE-2026-74553

Source
https://cve.org/CVERecord?id=CVE-2026-74553
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74553.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74553
Downstream
Published
2026-08-15T12:27:59Z
Modified
2026-08-21T03:30:11Z
Summary
hwmon: (nct6775-core) Fix number of temperature registers for NCT6116
Details

In the Linux kernel, the following vulnerability has been resolved:

hwmon: (nct6775-core) Fix number of temperature registers for NCT6116

Unlike NCT6106, NCT6116 only has three temperature registers, and with it only three temperature source and temperature source configuration registers. The register addresses match those of NCT6106 and can be re-used.

The code used a separate array to list the temperature source registers for NCT6116, but used the size of the NCT6106 register array to set the number of registers. The NCT6106 register array provides six addresses, while the temperature source register array for NCT6116 only provides three addresses. This causes a KASAN report.

BUG: KASAN: global-out-of-bounds in nct6775_probe+0x936/0x46f0 [nct6775] Read of size 2 at addr ffffffffc19561a6 by task modprobe/954 ... Call Trace: dump_stack+0x7d/0xa7 print_address_description.constprop.0+0x1c/0x220 ? __kasan_kmalloc.constprop.0+0xc9/0xd0 ? __kmalloc_node_track_caller+0x194/0x5b0 ? nct6775_probe+0x936/0x46f0 [nct6775] ? nct6775_probe+0x936/0x46f0 [nct6775] ...

Fix the problem by hard-coding the number of temperature and temperature configuration registers to three for NCT6116. Drop the unnecessary NCT6116_REG_TEMP_SOURCE array and re-use NCT6106_REG_TEMP_SOURCE.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74553.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
29c7cb485b321c024dedc168bcbb04451176b163
Fixed
739d7fc6b6f662c8286912157f0c4912388aa292
Fixed
9a87dfaa05c3c9d3a4cdb7eafc1ab4abc84f6eef
Fixed
16c45bb3d3434cfb9ea264fa52090d0823240465
Fixed
a42d727dae5701deac8bb2a75effadae7d681153
Fixed
a7f47f5246cd6c3199e5fb2d4109cc53e766e3f0
Fixed
b0e8adb2ccb43009796897ced09f91636685c9d3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74553.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.4.0
Fixed
6.1.183
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.151
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.103
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.44
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74553.json"