Junglewise Threat Intelligence

CVE-2024-46759: Linux Kernel integer underflow in adc128d818 hwmon driver

CVE-2024-46759 · Severity: high · CVSS 7.8 · Published 2024-09-18

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's hardware monitoring driver for the ADC128D818 chip, which is used to monitor system voltages and temperatures. An attacker with local access could provide specially crafted input to trigger an internal calculation error, potentially leading to system instability or unauthorized access. This issue has been resolved in recent kernel updates.

Technical details

An integer underflow vulnerability (CWE-191) exists in the adc128d818 hardware monitoring driver within the Linux kernel. The issue occurs in the `adc128_in_store` and `adc128_temp_store` functions when processing user input via `kstrtol()`. Specifically, calling `DIV_ROUND_CLOSEST()` on a large negative value (e.g., LONG_MIN) before applying `clamp_val()` causes an underflow. An attacker with local permissions to write to these sysfs attributes can trigger this behavior. The fix involves reordering the operations to clamp the value within safe bounds before performing the division. Patches have been backported to multiple stable kernel branches including 4.19, 5.4, 5.10, 5.15, 6.1, 6.6, and 6.10.

Affected products

  • Linux Linux Kernel up to 4.19.322, 4.20 to 5.4.284, 5.5 to 5.10.226, 5.11 to 5.15.167, 5.16 to 6.1.110, 6.2 to 6.6.51, 6.7 to 6.10.10

Timeline

  • 2024-09-18: advisory: CVE published by kernel.org
  • 2024-09-12: patched: Fix committed to stable kernel trees

References

Related threats