CVE-2026-68340: hwmon: occ: validate poll response sensor blocks
In the Linux kernel, the following vulnerability has been resolved:
hwmon: occ: validate poll response sensor blocks
The OCC poll response parser walks a counted list of sensor data blocks. It used the static backing-array capacity as the parse boundary, but a transport response makes only datalength bytes current and valid. A truncated response can therefore make the parser consume a block header or block extent outside the current response.
Use datalength as the parent boundary, prove the fixed poll header and each current block header before reading them, and prove the complete block before advancing. Keep parsed sensor metadata local until the complete response has passed validation, then publish it. Propagate malformed-response errors before publishing the OCC as active.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-68340?
CVE-2026-68340 has been assigned a risk score of 34.
What is the nature of the vulnerability in CVE-2026-68340?
CVE-2026-68340 involves an issue in the Linux kernel where the OCC poll response parser improperly handles sensor data blocks.
How do I fix CVE-2026-68340?
To remediate CVE-2026-68340, update your Linux kernel to the latest stable version that includes the security fix.
Which component is affected by CVE-2026-68340?
CVE-2026-68340 affects the hwmon (hardware monitoring) subsystem of the Linux kernel.
Is there a workaround for CVE-2026-68340?
Currently, there are no known workarounds for CVE-2026-68340; updating is the recommended solution.