PT-2026-61401 · Linux · Linux

CVE-2026-64084

·

Published

2026-07-19

·

Updated

2026-07-19

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the Linux kernel, the following vulnerability has been resolved:
hwmon: (pmbus/adm1266) cap PDIO scan in get multiple at ADM1266 PDIO NR
adm1266 gpio get multiple() iterates the PDIO portion of the caller-supplied mask using
for each set bit from(gpio nr, mask,
		   ADM1266 GPIO NR + ADM1266 PDIO STATUS) {
	...
}
where ADM1266 PDIO STATUS is the PMBus command code (0xE9, i.e. 233), not the number of PDIO pins. The intended upper bound is ADM1266 GPIO NR + ADM1266 PDIO NR = 25.
gpiolib hands in a mask sized for gc.ngpio (= 25 bits on this chip), so the iteration walks find next bit() up to 242, reading up to 217 extra bits (a handful of unsigned-long words: four on 64-bit, seven on 32-bit) of whatever lives past the end of the mask in the caller's stack. Any incidental set bit in that range then drives a set bit(gpio nr, bits) call that writes past the end of the caller-supplied bits array too -- both out-of-bounds.
Substitute ADM1266 PDIO NR for the constant so the scan stops at the last real PDIO bit.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-64084

Affected Products

Linux