-

CVE-2026-64083

hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors

In the Linux kernel, the following vulnerability has been resolved:

hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors

adm1266_gpio_get() and adm1266_gpio_get_multiple() both compose the
pin-status word as

	pins_status = read_buf[0] + (read_buf[1] << 8);

right after i2c_smbus_read_block_data(), guarding only against an
error return.  A well-behaved device returns 2 bytes for
GPIO_STATUS/PDIO_STATUS, but the helper happily reports a 0- or
1-byte response too.  If the device returns 0 bytes, both read_buf
slots are uninitialized stack memory; if it returns 1 byte, read_buf[1]
is.

The composed value then flows through set_bit() into the caller's
*bits in adm1266_gpio_get_multiple(), or into the return value of
adm1266_gpio_get(), and ends up in userspace via gpiolib (sysfs and
the char-dev ioctls).  That leaks a few bits of kernel stack per
request on any device whose firmware glitch, bus error, or hostile
slave produces a short block-read response.

Add the missing length check to both call sites and surface a short
response as -EIO.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version d98dfad35c38c037b37c4adc99df01da571031a5
Version < fd9196aad9e5a3845cea17de3405ebc700382142
Status affected
Version d98dfad35c38c037b37c4adc99df01da571031a5
Version < ee4799becf7d2af3778007e22c2e55c4009a49c7
Status affected
Version d98dfad35c38c037b37c4adc99df01da571031a5
Version < c603b6c6840ac0c6285f5eefea0de6242710af21
Status affected
Version d98dfad35c38c037b37c4adc99df01da571031a5
Version < a2d1c819348b36fccbbfcf37c5fa7a50a9b4528f
Status affected
Version d98dfad35c38c037b37c4adc99df01da571031a5
Version < ae25cf2ea9ebd06d7ad416647dbdc7b5d0172946
Status affected
Version d98dfad35c38c037b37c4adc99df01da571031a5
Version < eb3cd9bb590460c6127145cb245be925d23f5232
Status affected
Version d98dfad35c38c037b37c4adc99df01da571031a5
Version < 64fa9328948ddcc0f7f3c23ea1756c126d9dffac
Status affected
Version d98dfad35c38c037b37c4adc99df01da571031a5
Version < a7232f68c43ca62f545049b7f5fbfc75137b843b
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 5.10
Status affected
Version 0
Version < 5.10
Status unaffected
Version <= 5.10.*
Version 5.10.258
Status unaffected
Version <= 5.15.*
Version 5.15.209
Status unaffected
Version <= 6.1.*
Version 6.1.175
Status unaffected
Version <= 6.6.*
Version 6.6.142
Status unaffected
Version <= 6.12.*
Version 6.12.92
Status unaffected
Version <= 6.18.*
Version 6.18.34
Status unaffected
Version <= 7.0.*
Version 7.0.11
Status unaffected
Version <= *
Version 7.1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.083
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/fd9196aad9e5a3845cea17de3405ebc700382142
https://git.kernel.org/stable/c/ee4799becf7d2af3778007e22c2e55c4009a49c7
https://git.kernel.org/stable/c/c603b6c6840ac0c6285f5eefea0de6242710af21
https://git.kernel.org/stable/c/a2d1c819348b36fccbbfcf37c5fa7a50a9b4528f
https://git.kernel.org/stable/c/ae25cf2ea9ebd06d7ad416647dbdc7b5d0172946
https://git.kernel.org/stable/c/eb3cd9bb590460c6127145cb245be925d23f5232
https://git.kernel.org/stable/c/64fa9328948ddcc0f7f3c23ea1756c126d9dffac
https://git.kernel.org/stable/c/a7232f68c43ca62f545049b7f5fbfc75137b843b