Executive brief
The Linux kernel's hwmon ltc4282 driver is used to monitor power supply voltage and alarm conditions. A missing return statement in the minimum alarm voltage reading code causes out-of-bounds memory access when querying alarm status, potentially exposing sensitive kernel data or causing system instability.
Technical details
The vulnerability is a missing return statement (CWE-252) in the ltc4282_read_in() function when handling the hwmon_in_min_alarm attribute for the VGPIO channel. The ltc4282_read_alarm() function is called to read the alarm status, but the return value is not propagated back to the caller. This causes execution to fall through and access out-of-bounds memory when it should have returned. The flaw is in drivers/hwmon/ltc4282.c and affects systems running affected kernel versions that use this power supply monitoring driver. The vulnerability was discovered by static analysis (Coverity) and fixed by adding the missing return statement. No active exploitation in the wild is reported.
Affected products
- Linux Linux kernel Multiple versions from 2.6.11 through 6.9 and newer (ltc4282 driver available from kernel 5.18 onwards)
Timeline
- 2026-08-28: disclosed
- 2025-02-05: patched