CVE-2026-74549
Received Received - Intake

Buffer Overflow in Linux Kernel hwmon nct6775-core

Vulnerability report for CVE-2026-74549, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-15

Last updated on: 2026-08-15

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: hwmon: (nct6775-core) Prevent access to unsupported weight registers Sashiko reports: During initialization of the nct6116 chip, the driver sets data->pwm_num to 5. However, it assigns several NCT6106 register arrays (such as NCT6106_REG_WEIGHT_DUTY_STEP, NCT6106_REG_WEIGHT_TEMP_SEL, and NCT6106_REG_WEIGHT_TEMP_*) to data->REG_PWM and data->REG_WEIGHT_TEMP. These arrays only contain 3 elements. In nct6775_update_pwm(), the driver iterates up to data->pwm_num. If data->has_pwm has bits 3 or 4 set (which is structurally possible for nct6116), the loop attempts to read elements at index 3 and 4 from these 3-element arrays. This results in a global out-of-bounds read, which can be caught by KASAN. Furthermore, the driver uses these garbage out-of-bounds values as hardware register addresses for subsequent read and write operations. This leads to invalid hardware register access, potentially causing hardware misconfiguration or system crashes. The underlying problem is that the chip does support up to five fan control channels, but only the first three support weight control. Fix the problem by extending the affected weight register arrays with zeroed fields. The driver uses zeroed register addresses to determine if a register is supported or not, and skips accesses for unsupported registers.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-15
Last Modified
2026-08-15
Generated
2026-08-15
AI Q&A
2026-08-15
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Linux kernel's hwmon subsystem, specifically the nct6775-core driver for NCT6116 chips. It involves an out-of-bounds read during initialization where the driver incorrectly sets up register arrays for weight control. The driver tries to access unsupported registers beyond the array bounds, leading to potential hardware misconfiguration or system crashes.

Detection Guidance

This vulnerability is specific to the Linux kernel's hwmon subsystem, particularly the nct6775 driver for NCT6116 chips. Detection requires checking kernel logs for KASAN reports or out-of-bounds access errors during driver initialization. Monitor system logs with 'dmesg | grep -i kasan' or 'journalctl -k | grep -i nct6775'. If the system crashes or shows hardware misconfiguration, it may indicate exploitation.

Impact Analysis

This vulnerability could cause system instability, crashes, or hardware misconfiguration on systems using affected Linux kernels with NCT6116 chips. It may lead to improper fan control or thermal management, potentially damaging hardware or causing unexpected system behavior.

Mitigation Strategies

Update your Linux kernel to the latest stable version that includes the fix for CVE-2026-74549. If immediate kernel update is not possible, disable the nct6775 driver by blacklisting it with 'echo blacklist nct6775 | sudo tee /etc/modprobe.d/blacklist-nct6775.conf' and reboot. Avoid using systems with NCT6116 chips until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-74549. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart