Out-of-bounds read in Linux kernel - CVE-2026-74549
Published: August 16, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to out-of-bounds read in nct6775_update_pwm() in the nct6775-core hwmon driver when iterating over pwm channels for nct6116 weight-control registers. A local user can trigger access to unsupported weight registers to cause a denial of service.
The issue affects nct6116 configurations where bits 3 or 4 of has_pwm are set, causing out-of-bounds values to be used as hardware register addresses for subsequent read and write operations.
Affected software
Debian Linux
openEuler
kernel
bpftool
bpftool-debuginfo
kernel-debuginfo
kernel-debugsource
kernel-devel
kernel-headers
kernel-source
kernel-tools
kernel-tools-debuginfo
kernel-tools-devel
perf
perf-debuginfo
python3-perf
python3-perf-debuginfo
linux (Debian package)
How to mitigate CVE-2026-74549
kernel - update to 5.10.0-334.0.0.235
bpftool - update to 5.10.0-334.0.0.235
bpftool-debuginfo - update to 5.10.0-334.0.0.235
kernel-debuginfo - update to 5.10.0-334.0.0.235
kernel-debugsource - update to 5.10.0-334.0.0.235
kernel-devel - update to 5.10.0-334.0.0.235
kernel-headers - update to 5.10.0-334.0.0.235
kernel-source - update to 5.10.0-334.0.0.235
kernel-tools - update to 5.10.0-334.0.0.235
kernel-tools-debuginfo - update to 5.10.0-334.0.0.235
kernel-tools-devel - update to 5.10.0-334.0.0.235
perf - update to 5.10.0-334.0.0.235
perf-debuginfo - update to 5.10.0-334.0.0.235
python3-perf - update to 5.10.0-334.0.0.235
python3-perf-debuginfo - update to 5.10.0-334.0.0.235
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/1b722740ac5c2b2070f9ba922f4e0f227faf0246
- https://git.kernel.org/stable/c/25b528816f5d83be5236dc182692369e8c9402b0
- https://git.kernel.org/stable/c/4ad2972ef0e1bd1018ad7a72661a4636ed7daecc
- https://git.kernel.org/stable/c/689082a4cb166a7ae9729f7b12339e69fdad6c52
- https://git.kernel.org/stable/c/d0b704e569ac3b8416d8e02270cdc9bf830ed395