In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors adm1266_gpio_get() and adm1266_gpio_get_multiple() both compose the pin-status word as pins_status = read_buf[0] + (read_buf[1] << 8); right after i2c_smbus_read_block_data(), guarding only against an error return. A well-behaved device returns 2 bytes for GPIO_STATUS/PDIO_STATUS, but the helper happily reports a 0- or 1-byte response too. If the device returns 0 bytes, both read_buf slots are uninitialized stack memory; if it returns 1 byte, read_buf[1] is. The composed value then flows through set_bit() into the caller's *bits in adm1266_gpio_get_multiple(), or into the return value of adm1266_gpio_get(), and ends up in userspace via gpiolib (sysfs and the char-dev ioctls). That leaks a few bits of kernel stack per request on any device whose firmware glitch, bus error, or hostile slave produces a short block-read response. Add the missing length check to both call sites and surface a short response as -EIO.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 5.10CNA affecteddefault affected | |
| Linux | Linux | >= d98dfad35c38c037b37c4adc99df01da571031a5, < 64fa9328948ddcc0f7f3c23ea1756c126d9dffac, >= d98dfad35c38c037b37c4adc99df01da571031a5, < a2d1c819348b36fccbbfcf37c5fa7a50a9b4528f, >= d98dfad35c38c037b37c4adc99df01da571031a5, < a7232f68c43ca62f545049b7f5fbfc75137b843b, >= d98dfad35c38c037b37c4adc99df01da571031a5, < ae25cf2ea9ebd06d7ad416647dbdc7b5d0172946, >= d98dfad35c38c037b37c4adc99df01da571031a5, < c603b6c6840ac0c6285f5eefea0de6242710af21, >= d98dfad35c38c037b37c4adc99df01da571031a5, < eb3cd9bb590460c6127145cb245be925d23f5232, >= d98dfad35c38c037b37c4adc99df01da571031a5, < ee4799becf7d2af3778007e22c2e55c4009a49c7, >= d98dfad35c38c037b37c4adc99df01da571031a5, < fd9196aad9e5a3845cea17de3405ebc700382142CNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
No social media mentions found for this CVE.
No media coverage found for this CVE.
Linux kernel (Azure CVM) vulnerabilities
Jul 24, 2026Linux kernel vulnerabilities
Jul 24, 2026Linux kernel (Azure) vulnerabilities
Jul 24, 2026Linux kernel vulnerabilities
Jul 23, 2026Linux kernel (NVIDIA Tegra) vulnerabilities
Jul 21, 2026Linux kernel vulnerabilities
Jul 21, 2026