CVE-2026-74685

Source
https://cve.org/CVERecord?id=CVE-2026-74685
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74685.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74685
Downstream
Published
2026-08-22T15:32:51.493Z
Modified
2026-08-24T11:47:20.435123263Z
Summary
hwmon: (ltc4282) Clamp negative current limits
Details

In the Linux kernel, the following vulnerability has been resolved:

hwmon: (ltc4282) Clamp negative current limits

When a negative value is passed to ltc4282writecurr(), the signed long val is cast directly to u64:

drivers/hwmon/ltc4282.c:ltc4282writecurr() { /* need to pass it in millivolt */ u32 in = DIVROUNDCLOSEST_ULL((u64)val * st->rsense, DECA * MICRO); ... }

This cast converts negative inputs into large positive values. The subsequent division result overflows the u32 in variable, truncating to a pseudo-random positive value. When this is passed to ltc4282writevoltage_byte(), it is clamped to the maximum limit instead of zero.

Clamp val to 0 and to the maximum supported upper limit before the cast and assign the result to a 64-bit temporary variable before the division to avoid the underflow and an also possible overflow.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74685.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
cbc29538dbf7d7400f1ffc5dd5713e6a551463a0
Fixed
60e06c4dba696173982393252a40ceb7dd2eec18
Fixed
de58b90a4d1417c15b693eb04c0ce6bc925d84c6
Fixed
046e56b53c09375ef39903514496aa5508db9729
Fixed
e253dd5f9f6d875a317895bf43ec9534ed7523cb

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74685.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.9.0
Fixed
6.12.104
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.45
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74685.json"