SB20260816166 - Memory corruption in Linux kernel hwmon driver
Published: August 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Memory corruption (CVE-ID: CVE-2026-74551)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause memory corruption.
The vulnerability exists due to improper memory alignment in the nzxt-smart2 driver output buffer when sending output reports through the USB HID core for DMA. A local user can trigger device operations such as setting a fan speed or updating the interval to cause memory corruption.
This issue affects systems with non-coherent CPU architectures such as ARM or MIPS, where the corruption is immediate and deterministic due to cacheline sharing with adjacent variables.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/080bbf42faf77e6489ab30d5114c5f8f6ccbb1b8
- https://git.kernel.org/stable/c/2332d35aaf206c17acf848522817252732596676
- https://git.kernel.org/stable/c/51a76bc1b8e717ee3fc0d84f15ac51490ca5f76f
- https://git.kernel.org/stable/c/6a2dbce5da2d2163a5b684acf68a0e54582ff0fa
- https://git.kernel.org/stable/c/70ad543ce81f368411b6c721265a3b2d7ab4fda4