PT-2026-61283 · Linux · Linux

CVE-2026-63966

·

Published

2026-07-19

·

Updated

2026-07-19

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
iio: imu: adis16550: fix stack leak in trigger handler
adis16550 trigger handler() declares the scan data array on the stack without initializing it. The memcpy() at the bottom fills only the first 28 bytes (TEMP + 6 channels of GYRO/ACCEL data), and iio push to buffers with timestamp() writes the s64 timestamp at the 8-byte-aligned offset 32. Bytes 28-31 remain uninitialized stack data which leaks to userspace on ever trigger.
Fix this all by just zero-initializing the structure on the stack.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-63966

Affected Products

Linux