PT-2026-61401 · Linux · Linux
CVE-2026-64084
·
Published
2026-07-19
·
Updated
2026-07-19
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
In the Linux kernel, the following vulnerability has been resolved:
hwmon: (pmbus/adm1266) cap PDIO scan in get multiple at ADM1266 PDIO NR
adm1266 gpio get multiple() iterates the PDIO portion of the
caller-supplied mask using
for each set bit from(gpio nr, mask,
ADM1266 GPIO NR + ADM1266 PDIO STATUS) {
...
}where ADM1266 PDIO STATUS is the PMBus command code (0xE9, i.e. 233),
not the number of PDIO pins. The intended upper bound is
ADM1266 GPIO NR + ADM1266 PDIO NR = 25.
gpiolib hands in a mask sized for gc.ngpio (= 25 bits on this chip),
so the iteration walks find next bit() up to 242, reading up to 217
extra bits (a handful of unsigned-long words: four on 64-bit, seven
on 32-bit) of whatever lives past the end of the mask in the
caller's stack. Any incidental set bit in that range then drives a
set bit(gpio nr, bits) call that writes past the end of the
caller-supplied bits array too -- both out-of-bounds.
Substitute ADM1266 PDIO NR for the constant so the scan stops at the
last real PDIO bit.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux