Description
In the Linux kernel, the following vulnerability has been resolved:

hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read

If the fan data becomes 0 between the FAN_DATA_VALID() check and the
FAN_PERIOD_TO_RPM() conversion, it will result in a divide-by-zero crash
due to a race with a concurrent update of the cached fan value.

Fix a TOCTOU issue by reading fan data once.
Published: 2026-08-15
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A race condition in the Linux kernel’s adt7470 hardware monitoring driver causes a divide‑by‑zero crash when fan data changes to zero between a validity check and the conversion to RPM. The conflicting updates of the cached fan value trigger the faulty calculation, leading to a kernel panic.

Affected Systems

The flaw is present in any Linux kernel version that includes the adt7470 driver before the patch is applied. No specific kernel releases are identified, so all affected builds containing the module are vulnerable until updated.

Risk and Exploitability

The EPSS score of less than 1% and absence from CISA KEV suggest a low exploitation probability. The CVSS score of 5.5 indicates medium severity, reflecting the kernel crash impact. The likely attack vector requires local execution with sufficient privileges to force fan monitoring operations; however, this requirement is inferred from the nature of the kernel driver and is not explicitly stated in the provided description.

Generated by OpenCVE AI on August 21, 2026 at 23:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Linux kernel to a revision that includes the adt7470 divide‑by‑zero fix commit.
  • Reboot the system to load the patched driver and validate that the crash no longer occurs.
  • If an immediate kernel upgrade is not possible, disable the adt7470 driver or fan‑monitoring subsystem by removing the module or setting its kernel configuration to "n" to prevent fan speed reads that could trigger the fault.

Generated by OpenCVE AI on August 21, 2026 at 23:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6466-1 linux security update
History

Fri, 21 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Fri, 21 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Low


Wed, 19 Aug 2026 17:00:00 +0000


Sat, 15 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
CWE-369

Sat, 15 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read If the fan data becomes 0 between the FAN_DATA_VALID() check and the FAN_PERIOD_TO_RPM() conversion, it will result in a divide-by-zero crash due to a race with a concurrent update of the cached fan value. Fix a TOCTOU issue by reading fan data once.
Title hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-19T16:38:34.886Z

Reserved: 2026-08-15T05:44:03.914Z

Link: CVE-2026-74546

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T13:17:59.950

Modified: 2026-08-19T17:21:09.453

Link: CVE-2026-74546

cve-icon Redhat

Severity : Low

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-74546 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T23:15:05Z

Weaknesses