CVE-2026-64087 Details
Description
In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus/adm1266) reject implausible blackbox record_count adm1266_nvmem_read_blackbox() loops over a record_count that comes straight from byte 3 of the BLACKBOX_INFO response. The destination buffer is data->dev_mem, sized for the nvmem cell's declared 2048 bytes (ADM1266_BLACKBOX_MAX_RECORDS * ADM1266_BLACKBOX_SIZE = 32 * 64). A device that reports a record_count greater than 32 -- whether due to firmware bugs, bus corruption, or a non-responsive slave returning 0xff -- would walk read_buff past the end of the dev_mem allocation on the trailing iterations. Cap record_count at ADM1266_BLACKBOX_MAX_RECORDS (introduced here) before entering the loop and return -EIO on any larger value, so a malformed BLACKBOX_INFO response cannot drive the loop out of bounds.
A vulnerability in the Linux kernel's handling of the ADM1266 PMBus device can lead to a buffer overflow. The issue arises in the 'adm1266_nvmem_read_blackbox' function, which processes a 'record_count' value from the BLACKBOX_INFO response. The function's destination buffer is limited to 2048 bytes, but a device may incorrectly report a higher record count, causing the function to read beyond the allocated memory. This flaw can be triggered by firmware errors, bus issues, or unresponsive devices. The vulnerability affects several versions of the Linux kernel.
The vulnerability has been fixed in the Linux kernel. Users should upgrade to the latest version.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/0e791cd0140fb136083565aadfbe0f705aa260d0 | kernel.org | Patch |
| https://git.kernel.org/stable/c/231db52a5b64d0a9769e298dadc148e1f79b26a6 | kernel.org | Patch |
| https://git.kernel.org/stable/c/4afca954622d672ea65ed961bed01cf91caa034e | kernel.org | Patch |
| https://git.kernel.org/stable/c/5469e1e7c411acc15fdd8262c99c3ebd9defd594 | kernel.org | Patch |
| https://git.kernel.org/stable/c/75c862adf3d3caab4f49bb3530723c215376e37c | kernel.org | Patch |
| https://git.kernel.org/stable/c/adcb163ad7cacca317872fc62bd8885e842e45e3 | kernel.org | Patch |
| https://git.kernel.org/stable/c/c2c56092710fe8a893b67b5a3d7e62808d02d84d | kernel.org | Patch |
| https://git.kernel.org/stable/c/f85c81e93dbd6915970bd5f3bffcf62633c4c54c | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 5.10, < 5.10.258 >= 5.11, < 5.15.209 >= 5.16, < 6.1.175 >= 6.2, < 6.6.142 >= 6.7, < 6.12.92 >= 6.13, < 6.18.34 >= 6.19, < 7.0.11 7.1 rc1 7.1 rc2 7.1 rc3 7.1 rc4 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 3, 2026 | Initial Analysis | [email protected] |
| Jul 19, 2026 | New CVE Received | kernel.org |