{"id":"CVE-2026-68340","summary":"hwmon: occ: validate poll response sensor blocks","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: occ: validate poll response sensor blocks\n\nThe OCC poll response parser walks a counted list of sensor data blocks.\nIt used the static backing-array capacity as the parse boundary, but a\ntransport response makes only data_length bytes current and valid. A\ntruncated response can therefore make the parser consume a block header or\nblock extent outside the current response.\n\nUse data_length as the parent boundary, prove the fixed poll header and\neach current block header before reading them, and prove the complete block\nbefore advancing. Keep parsed sensor metadata local until the complete\nresponse has passed validation, then publish it. Propagate\nmalformed-response errors before publishing the OCC as active.","modified":"2026-08-12T04:19:22.708171316Z","published":"2026-08-10T12:03:16.552Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68340.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/112525534ab5cff482d35897ca4ca11fd3a76f46"},{"type":"WEB","url":"https://git.kernel.org/stable/c/538d862cc0dbd5c732fe26d5aad98eae039e6676"},{"type":"WEB","url":"https://git.kernel.org/stable/c/54cb78eceb4e286ccd5a5c01a4632157860d47f0"},{"type":"WEB","url":"https://git.kernel.org/stable/c/70e76e700fc6c46afb4e17aec099a1ea089b4a22"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b042e538e98b939fccfffc464e2c34c29f0e96ef"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68340.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-68340"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"aa195fe49b033db545ad986cdb2c431c37bea557"},{"fixed":"112525534ab5cff482d35897ca4ca11fd3a76f46"},{"fixed":"54cb78eceb4e286ccd5a5c01a4632157860d47f0"},{"fixed":"538d862cc0dbd5c732fe26d5aad98eae039e6676"},{"fixed":"b042e538e98b939fccfffc464e2c34c29f0e96ef"},{"fixed":"70e76e700fc6c46afb4e17aec099a1ea089b4a22"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68340.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.0.0"},{"fixed":"6.6.148"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.101"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.42"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.1.6"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68340.json"}}],"schema_version":"1.9.0"}