{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-74549","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-15T05:44:03.915Z","datePublished":"2026-08-15T12:27:56.993Z","dateUpdated":"2026-08-19T16:38:42.442Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-19T16:38:42.442Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (nct6775-core) Prevent access to unsupported weight registers\n\nSashiko reports:\n\nDuring initialization of the nct6116 chip, the driver sets data->pwm_num\nto 5. However, it assigns several NCT6106 register arrays (such as\nNCT6106_REG_WEIGHT_DUTY_STEP, NCT6106_REG_WEIGHT_TEMP_SEL, and\nNCT6106_REG_WEIGHT_TEMP_*) to data->REG_PWM and data->REG_WEIGHT_TEMP.\nThese arrays only contain 3 elements.\n\nIn nct6775_update_pwm(), the driver iterates up to data->pwm_num. If\ndata->has_pwm has bits 3 or 4 set (which is structurally possible for\nnct6116), the loop attempts to read elements at index 3 and 4 from these\n3-element arrays. This results in a global out-of-bounds read, which can\nbe caught by KASAN.\n\nFurthermore, the driver uses these garbage out-of-bounds values as\nhardware register addresses for subsequent read and write operations. This\nleads to invalid hardware register access, potentially causing hardware\nmisconfiguration or system crashes.\n\nThe underlying problem is that the chip does support up to five fan\ncontrol channels, but only the first three support weight control.\nFix the problem by extending the affected weight register arrays with\nzeroed fields. The driver uses zeroed register addresses to determine\nif a register is supported or not, and skips accesses for unsupported\nregisters."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - Exploitation requires local access to hwmon sysfs under /sys/class/hwmon/; any read or write of sensor attributes invokes nct6775_update_device() and reaches the vulnerable nct6775_update_pwm() path via the platform Super I/O driver.\nAC:L - On affected NCT6116 systems with PWM channels 4-5 enabled (has_pwm bits 3-4), triggering is reliable by reading or writing any exposed hwmon attribute; no race or special victim state is required beyond standard sysfs access.\nPR:L - Fan and PWM sysfs attributes are created with mode 0644 and the driver performs no capability or permission checks beyond standard file permissions, so any unprivileged local user can trigger the vulnerable update and store paths.\nUI:N - No victim interaction is required; the attacker directly reads or writes hwmon sysfs files to invoke nct6775_update_pwm() and associated store handlers without needing another user to perform any action.\nS:U - The vulnerability corrupts kernel driver state and on-chip Super I/O fan/thermal registers on the same host; it does not cross a VM, container, or IOMMU security boundary to impact a separate authority.\nC:H - Indexing past the three-element NCT6106 weight register arrays causes a global out-of-bounds read in kernel .rodata (KASAN-detectable), and the resulting bogus register addresses drive unintended hardware reads whose values are cached and returned through sysfs.\nI:H - Out-of-bounds indices supply valid but incorrect Super I/O register addresses (e.g. auto-temperature registers of other PWM channels) to nct6775_write_value() via writable 0644 sysfs stores, enabling cross-channel fan/thermal misconfiguration.\nA:H - Misdirected reads and writes to wrong Super I/O control registers can corrupt active fan/thermal management on industrial/embedded systems with five PWM channels, potentially causing kernel faults, thermal emergency shutdown, or sustained denial of service."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/hwmon/nct6775-core.c"],"versions":[{"version":"29c7cb485b321c024dedc168bcbb04451176b163","lessThan":"0d11b2a10269ace29832f584d207ff3768f79dc5","status":"affected","versionType":"git"},{"version":"29c7cb485b321c024dedc168bcbb04451176b163","lessThan":"4a77f1d72c6db04cbbfab0250292ac71fdea5f0a","status":"affected","versionType":"git"},{"version":"29c7cb485b321c024dedc168bcbb04451176b163","lessThan":"513d847f7a95bbdbeaaf55fb942c38992587734f","status":"affected","versionType":"git"},{"version":"29c7cb485b321c024dedc168bcbb04451176b163","lessThan":"25b528816f5d83be5236dc182692369e8c9402b0","status":"affected","versionType":"git"},{"version":"29c7cb485b321c024dedc168bcbb04451176b163","lessThan":"689082a4cb166a7ae9729f7b12339e69fdad6c52","status":"affected","versionType":"git"},{"version":"29c7cb485b321c024dedc168bcbb04451176b163","lessThan":"1b722740ac5c2b2070f9ba922f4e0f227faf0246","status":"affected","versionType":"git"},{"version":"29c7cb485b321c024dedc168bcbb04451176b163","lessThan":"4ad2972ef0e1bd1018ad7a72661a4636ed7daecc","status":"affected","versionType":"git"},{"version":"29c7cb485b321c024dedc168bcbb04451176b163","lessThan":"d0b704e569ac3b8416d8e02270cdc9bf830ed395","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/hwmon/nct6775-core.c"],"versions":[{"version":"5.4","status":"affected"},{"version":"0","lessThan":"5.4","status":"unaffected","versionType":"semver"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.151","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.103","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.44","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.8","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4","versionEndExcluding":"5.10.265"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4","versionEndExcluding":"5.15.216"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4","versionEndExcluding":"6.1.183"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4","versionEndExcluding":"6.6.151"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4","versionEndExcluding":"6.12.103"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4","versionEndExcluding":"6.18.44"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4","versionEndExcluding":"7.1.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/0d11b2a10269ace29832f584d207ff3768f79dc5"},{"url":"https://git.kernel.org/stable/c/4a77f1d72c6db04cbbfab0250292ac71fdea5f0a"},{"url":"https://git.kernel.org/stable/c/513d847f7a95bbdbeaaf55fb942c38992587734f"},{"url":"https://git.kernel.org/stable/c/25b528816f5d83be5236dc182692369e8c9402b0"},{"url":"https://git.kernel.org/stable/c/689082a4cb166a7ae9729f7b12339e69fdad6c52"},{"url":"https://git.kernel.org/stable/c/1b722740ac5c2b2070f9ba922f4e0f227faf0246"},{"url":"https://git.kernel.org/stable/c/4ad2972ef0e1bd1018ad7a72661a4636ed7daecc"},{"url":"https://git.kernel.org/stable/c/d0b704e569ac3b8416d8e02270cdc9bf830ed395"}],"title":"hwmon: (nct6775-core) Prevent access to unsupported weight registers","x_generator":{"engine":"bippy-1.2.0"}}}}