Bug 2517033 (CVE-2026-74551)
| Summary: | CVE-2026-74551 kernel: hwmon: (nzxt-smart2) DMA-align output buffer | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | rhel-process-autobot, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in the Linux kernel's `hwmon: (nzxt-smart2)` driver. This vulnerability allows for immediate and deterministic memory corruption on systems with non-coherent CPU architectures, such as ARM or MIPS. When operations like setting a fan speed or updating an interval trigger a USB Direct Memory Access (DMA) mapping, the DMA process can corrupt adjacent variables due to cacheline sharing. This issue is resolved by aligning the output buffer to prevent unintended data corruption.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-08-15 12:46:04 UTC
|