Description
In the Linux kernel, the following vulnerability has been resolved:

hwmon: (ltc4282) Clamp negative current limits

When a negative value is passed to ltc4282_write_curr(), the signed long
val is cast directly to u64:

drivers/hwmon/ltc4282.c:ltc4282_write_curr() {
/* need to pass it in millivolt */
u32 in = DIV_ROUND_CLOSEST_ULL((u64)val * st->rsense, DECA * MICRO);
...
}

This cast converts negative inputs into large positive values. The
subsequent division result overflows the u32 in variable, truncating
to a pseudo-random positive value. When this is passed to
ltc4282_write_voltage_byte(), it is clamped to the maximum limit instead
of zero.

Clamp val to 0 and to the maximum supported upper limit before the cast
and assign the result to a 64-bit temporary variable before the division
to avoid the underflow and an also possible overflow.
Published: 2026-08-22
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Potential hardware damage from misconfigured current limits
Action: Apply Patch
AI Analysis

Impact

The vulnerability occurs in the Linux kernel’s LTC4282 hardware monitor driver when a negative current value is supplied to the write routine. The signed long value is cast to an unsigned 64‑bit variable, turning the negative input into a very large positive number. Subsequent arithmetic overflows and truncation result in an apparently random positive value that the driver finally clamps to the maximum permitted current limit instead of zero, preventing the intended low‑current protection. This flaw could allow an over‑current condition that may damage the hardware component or compromise system reliability.

Affected Systems

Any Linux system that builds the kernel with the ltc4282 driver enabled is affected. The driver is used for power monitoring on certain boards and is included in the mainstream kernel tree. The exact kernel version is not specified, so any kernel snapshot containing the ltc4282 code is potentially vulnerable until the patch is merged.

Risk and Exploitability

Based on the description, the flaw requires a negative value to be written through the driver’s write interface, a capability that is available only to kernel code or privileged processes. No publicly available remote exploit or proof‑of‑concept has been documented, and the issue is not listed in CISA’s KEV catalog. The EPSS score is < 1%, indicating a very low publicly observed exploitation probability. The CVSS score of 5.5 indicates a moderate severity. Because the attack vector needs kernel privileges, the risk is limited to compromised or locally privileged adversaries. The potential impact, if exploited, is over‑current that could damage the device or destabilize the system, but the very low EPSS score reduces the immediacy of this threat compared to publicly exposed vulnerabilities.

Generated by OpenCVE AI on August 25, 2026 at 16:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that incorporates the latest ltc4282 driver patch that clamps negative values before casting
  • If the affected driver must remain enabled, audit and restrict any user‑space utilities or scripts that call write_curr() so they never provide negative values, enforcing a minimum of zero
  • As a permanent fix, ensure kernel builds include the protective change shown in commit 046e56b53c09375ef39903514496aa5508db9729, which properly validates and limits current limits before conversion

Generated by OpenCVE AI on August 25, 2026 at 16:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6466-1 linux security update
History

Tue, 25 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-195

Tue, 25 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Sat, 22 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190
CWE-195

Sat, 22 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: hwmon: (ltc4282) Clamp negative current limits When a negative value is passed to ltc4282_write_curr(), the signed long val is cast directly to u64: drivers/hwmon/ltc4282.c:ltc4282_write_curr() { /* need to pass it in millivolt */ u32 in = DIV_ROUND_CLOSEST_ULL((u64)val * st->rsense, DECA * MICRO); ... } This cast converts negative inputs into large positive values. The subsequent division result overflows the u32 in variable, truncating to a pseudo-random positive value. When this is passed to ltc4282_write_voltage_byte(), it is clamped to the maximum limit instead of zero. Clamp val to 0 and to the maximum supported upper limit before the cast and assign the result to a 64-bit temporary variable before the division to avoid the underflow and an also possible overflow.
Title hwmon: (ltc4282) Clamp negative current limits
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-22T15:32:51.493Z

Reserved: 2026-08-15T05:44:03.926Z

Link: CVE-2026-74685

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-22T16:16:42.870

Modified: 2026-08-22T16:16:42.870

Link: CVE-2026-74685

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-22T00:00:00Z

Links: CVE-2026-74685 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T16:30:06Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound