-

CVE-2026-63934

iio: gyro: itg3200: fix i2c read into the wrong stack location

In the Linux kernel, the following vulnerability has been resolved:

iio: gyro: itg3200: fix i2c read into the wrong stack location

itg3200_read_all_channels() takes `__be16 *buf' as a parameter and
fills the i2c_msg destination as `(char *)&buf'. Since `buf' is the
parameter (a pointer), `&buf' is the address of the local pointer
slot on the stack of itg3200_read_all_channels(), not the address
of the caller's scan buffer. The (char *) cast hides the type
mismatch.

i2c_transfer() therefore writes ITG3200_SCAN_ELEMENTS * sizeof(s16)
= 8 bytes into the parameter's stack slot, which is discarded when
the function returns. The caller's scan buffer in
itg3200_trigger_handler() is never written to, so
iio_push_to_buffers_with_timestamp() pushes uninitialised stack
contents to userspace via /dev/iio:deviceX every scan -- both a
functional bug (no actual gyroscope or temperature data is
delivered through the triggered buffer) and an information leak.

The non-buffered read_raw() path is unaffected: it goes through
itg3200_read_reg_s16() which uses `&out' on a local s16 value,
where that is correct.

Drop the spurious `&' so the i2c read writes into the caller's
buffer.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 9dbf091da080508e9f632d307f357beb79a0766b
Version < 90e809376b0f0d1ddec2eec954aecdd2a5b40b0e
Status affected
Version 9dbf091da080508e9f632d307f357beb79a0766b
Version < 8654b5e2617819ff4f7c78071dfd0275e971a9b6
Status affected
Version 9dbf091da080508e9f632d307f357beb79a0766b
Version < b64dd5f3b38911054cbcc570df617e3e8e75e562
Status affected
Version 9dbf091da080508e9f632d307f357beb79a0766b
Version < 31bbd4b87dd6701fa10e03ba7f6268e49e178d16
Status affected
Version 9dbf091da080508e9f632d307f357beb79a0766b
Version < 63203bd072b613c18c237b906b1c9d2dc4527337
Status affected
Version 9dbf091da080508e9f632d307f357beb79a0766b
Version < 15a0b3f33ffb6c78b3de6f69b026ceb09b973dd1
Status affected
Version 9dbf091da080508e9f632d307f357beb79a0766b
Version < cfc3283859cfdeacadf80d5e6880bdf871ffeaa6
Status affected
Version 9dbf091da080508e9f632d307f357beb79a0766b
Version < 6bdc3023d62ed5c7d591f0eb27a5adb37fb892ae
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 3.9
Status affected
Version 0
Version < 3.9
Status unaffected
Version <= 5.10.*
Version 5.10.259
Status unaffected
Version <= 5.15.*
Version 5.15.210
Status unaffected
Version <= 6.1.*
Version 6.1.176
Status unaffected
Version <= 6.6.*
Version 6.6.143
Status unaffected
Version <= 6.12.*
Version 6.12.93
Status unaffected
Version <= 6.18.*
Version 6.18.35
Status unaffected
Version <= 7.0.*
Version 7.0.12
Status unaffected
Version <= *
Version 7.1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.114
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/90e809376b0f0d1ddec2eec954aecdd2a5b40b0e
https://git.kernel.org/stable/c/8654b5e2617819ff4f7c78071dfd0275e971a9b6
https://git.kernel.org/stable/c/b64dd5f3b38911054cbcc570df617e3e8e75e562
https://git.kernel.org/stable/c/31bbd4b87dd6701fa10e03ba7f6268e49e178d16
https://git.kernel.org/stable/c/63203bd072b613c18c237b906b1c9d2dc4527337
https://git.kernel.org/stable/c/15a0b3f33ffb6c78b3de6f69b026ceb09b973dd1
https://git.kernel.org/stable/c/cfc3283859cfdeacadf80d5e6880bdf871ffeaa6
https://git.kernel.org/stable/c/6bdc3023d62ed5c7d591f0eb27a5adb37fb892ae