Time-of-check Time-of-use (TOCTOU) Race Condition in Linux kernel - CVE-2026-74546
Published: August 16, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a time-of-check time-of-use race condition in the adt7470 fan speed read handler when reading cached fan data during fan speed conversion. A local user can trigger concurrent updates of the cached fan value to cause a denial of service.
The issue can lead to a divide-by-zero crash if the fan data changes to 0 between the validity check and the RPM conversion.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74546
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/1b46fe9dc8f8de59310f37e6c5e5c0e05ded46c3
- https://git.kernel.org/stable/c/76963b04b2d1c648d69949d8dd521e1ff7f40b51
- https://git.kernel.org/stable/c/832069bec79cf6f903441c5769d3cdba95d0af33
- https://git.kernel.org/stable/c/96ad57d31763559d376416cdf3bf5ae79bbbebec
- https://git.kernel.org/stable/c/d328175045176f85c15c369bd21dc551351e7935