Answer in brief
CVE-2026-74685 records a Unknown severity vulnerability in hwmon: (ltc4282) Clamp negative current limits. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=cbc29538dbf7d7400f1ffc5dd5713e6a551463a0 <60e06c4dba696173982393252a40ceb7dd2eec18 || >=cbc29538dbf7d7400f1ffc5dd5713e6a551463a0 <de58b90a4d1417c15b693eb04c0ce6bc925d84c6 || >=cbc29538dbf7d7400f1ffc5dd5713e6a551463a0 <046e56b53c09375ef39903514496aa5508db9729 || >=cbc29538dbf7d7400f1ffc5dd5713e6a551463a0 <e253dd5f9f6d875a317895bf43ec9534ed7523cb | 60e06c4dba696173982393252a40ceb7dd2eec18, de58b90a4d1417c15b693eb04c0ce6bc925d84c6, 046e56b53c09375ef39903514496aa5508db9729, e253dd5f9f6d875a317895bf43ec9534ed7523cb |
| Linux/Linuxgeneric | 6.9 | Not reported |
Published upstream
Aug 22, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 22, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 22, 2026
In the Linux kernel, the following vulnerability has been resolved: hwmon: (ltc4282) Clamp negative current limits When a negative value is passed to ltc4282_write_curr(), the signed long val is cast directly to u64: drivers/hwmon/ltc4282.c:ltc4282_write_curr() { /* need to pass it in millivolt */ u32 in = DIV_ROUND_CLOSEST_ULL((u64)val * st->rsense, DECA * MICRO); ... } This cast converts negative inputs into large positive values. The subsequent division result overflows the u32 in variable, truncating to a pseudo-random positive value. When this is passed to ltc4282_write_voltage_byte(), it is clamped to the maximum limit instead of zero. Clamp val to 0 and to the maximum supported upper limit before the cast and assign the result to a 64-bit temporary variable before the division to avoid the underflow and an also possible overflow.
Quoted source text, attributed separately from HOL analysis.