Commit e253dd5f9f6d for kernel

commit e253dd5f9f6d875a317895bf43ec9534ed7523cb
Author: Guenter Roeck <linux@roeck-us.net>
Date:   Tue Aug 4 16:26:05 2026 -0700

    hwmon: (ltc4282) Clamp negative current limits

    When a negative value is passed to ltc4282_write_curr(), the signed long
    val is cast directly to u64:

    drivers/hwmon/ltc4282.c:ltc4282_write_curr() {
            /* need to pass it in millivolt */
            u32 in = DIV_ROUND_CLOSEST_ULL((u64)val * st->rsense, DECA * MICRO);
            ...
    }

    This cast converts negative inputs into large positive values. The
    subsequent division result overflows the u32 in variable, truncating
    to a pseudo-random positive value. When this is passed to
    ltc4282_write_voltage_byte(), it is clamped to the maximum limit instead
    of zero.

    Clamp val to 0 and to the maximum supported upper limit before the cast
    and assign the result to a 64-bit temporary variable before the division
    to avoid the underflow and an also possible overflow.

    Reported-by: Sashiko <sashiko-bot@kernel.org>
    Fixes: cbc29538dbf7d ("hwmon: Add driver for LTC4282")
    Cc: Nuno Sa <nuno.sa@analog.com>
    Reviewed-by: Nuno Sá <nuno.sa@analog.com>
    Signed-off-by: Guenter Roeck <linux@roeck-us.net>

diff --git a/drivers/hwmon/ltc4282.c b/drivers/hwmon/ltc4282.c
index bb7f6727c44d..bb1bcb369016 100644
--- a/drivers/hwmon/ltc4282.c
+++ b/drivers/hwmon/ltc4282.c
@@ -14,6 +14,7 @@
 #include <linux/hwmon.h>
 #include <linux/i2c.h>
 #include <linux/math.h>
+#include <linux/math64.h>
 #include <linux/minmax.h>
 #include <linux/module.h>
 #include <linux/regmap.h>
@@ -929,8 +930,11 @@ static int ltc4282_curr_reset_hist(struct ltc4282_state *st)
 static int ltc4282_write_curr(struct ltc4282_state *st, u32 attr,
 			      long val)
 {
+	s32 ulimit = min_t(u64, INT_MAX,
+			   div_u64((u64)INT_MAX * DECA * MICRO, st->rsense));
+	u64 val64 = clamp(val, 0, ulimit);
 	/* need to pass it in millivolt */
-	u32 in = DIV_ROUND_CLOSEST_ULL((u64)val * st->rsense, DECA * MICRO);
+	u32 in = DIV_ROUND_CLOSEST_ULL(val64 * st->rsense, DECA * MICRO);

 	switch (attr) {
 	case hwmon_curr_max: