CVE-2026-64083 Details
Description
In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors adm1266_gpio_get() and adm1266_gpio_get_multiple() both compose the pin-status word as pins_status = read_buf[0] + (read_buf[1] << 8); right after i2c_smbus_read_block_data(), guarding only against an error return. A well-behaved device returns 2 bytes for GPIO_STATUS/PDIO_STATUS, but the helper happily reports a 0- or 1-byte response too. If the device returns 0 bytes, both read_buf slots are uninitialized stack memory; if it returns 1 byte, read_buf[1] is. The composed value then flows through set_bit() into the caller's *bits in adm1266_gpio_get_multiple(), or into the return value of adm1266_gpio_get(), and ends up in userspace via gpiolib (sysfs and the char-dev ioctls). That leaks a few bits of kernel stack per request on any device whose firmware glitch, bus error, or hostile slave produces a short block-read response. Add the missing length check to both call sites and surface a short response as -EIO.
A vulnerability exists in the Linux kernel's handling of GPIO accessors for the ADM1266 PMBus device. The issue arises in the functions 'adm1266_gpio_get()' and 'adm1266_gpio_get_multiple()', which read GPIO status data via I2C block reads. These functions expect a response of two bytes but do not properly validate the length of the response before processing it. As a result, if a device returns fewer than two bytes, the functions can inadvertently expose uninitialized stack memory to userspace through the GPIO subsystem. This vulnerability can be triggered by any device that sends a short block-read response due to a firmware error, bus issue, or malicious behavior.
The vulnerability has been addressed by adding the missing length checks to both GPIO accessor functions. Users should update to the latest version of the Linux kernel where this fix has been applied.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/64fa9328948ddcc0f7f3c23ea1756c126d9dffac | kernel.org | Patch |
| https://git.kernel.org/stable/c/a2d1c819348b36fccbbfcf37c5fa7a50a9b4528f | kernel.org | Patch |
| https://git.kernel.org/stable/c/a7232f68c43ca62f545049b7f5fbfc75137b843b | kernel.org | Patch |
| https://git.kernel.org/stable/c/ae25cf2ea9ebd06d7ad416647dbdc7b5d0172946 | kernel.org | Patch |
| https://git.kernel.org/stable/c/c603b6c6840ac0c6285f5eefea0de6242710af21 | kernel.org | Patch |
| https://git.kernel.org/stable/c/eb3cd9bb590460c6127145cb245be925d23f5232 | kernel.org | Patch |
| https://git.kernel.org/stable/c/ee4799becf7d2af3778007e22c2e55c4009a49c7 | kernel.org | Patch |
| https://git.kernel.org/stable/c/fd9196aad9e5a3845cea17de3405ebc700382142 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 5.10, < 5.10.258 >= 5.11, < 5.15.209 >= 5.16, < 6.1.175 >= 6.2, < 6.6.142 >= 6.7, < 6.12.92 >= 6.13, < 6.18.34 >= 6.19, < 7.0.11 7.1 rc1 7.1 rc2 7.1 rc3 7.1 rc4 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 3, 2026 | Initial Analysis | [email protected] |
| Jul 19, 2026 | New CVE Received | kernel.org |