CVE-2026-64084: hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR

Greg Kroah-Hartman <[email protected]>
Newsgroups org.kernel.vger.linux-cve-announce
Message-ID <2026071916-CVE-2026-64084-b17b@gregkh>
From: Greg Kroah-Hartman <[email protected]>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR

adm1266_gpio_get_multiple() iterates the PDIO portion of the
caller-supplied mask using

	for_each_set_bit_from(gpio_nr, mask,
			      ADM1266_GPIO_NR + ADM1266_PDIO_STATUS) {
		...
	}

where ADM1266_PDIO_STATUS is the PMBus command code (0xE9, i.e. 233),
not the number of PDIO pins.  The intended upper bound is
ADM1266_GPIO_NR + ADM1266_PDIO_NR = 25.

gpiolib hands in a mask sized for gc.ngpio (= 25 bits on this chip),
so the iteration walks find_next_bit() up to 242, reading up to 217
extra bits (a handful of unsigned-long words: four on 64-bit, seven
on 32-bit) of whatever lives past the end of the mask in the
caller's stack.  Any incidental set bit in that range then drives a
set_bit(gpio_nr, bits) call that writes past the end of the
caller-supplied bits array too -- both out-of-bounds.

Substitute ADM1266_PDIO_NR for the constant so the scan stops at the
last real PDIO bit.

The Linux kernel CVE team has assigned CVE-2026-64084 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 5.10 with commit d98dfad35c38c037b37c4adc99df01da571031a5 and fixed in 5.10.258 with commit d0593e15fdeb56048a72c5c6e720f702759d0ccd
	Issue introduced in 5.10 with commit d98dfad35c38c037b37c4adc99df01da571031a5 and fixed in 5.15.209 with commit 17cee2f59029039416e8f6303050038eb59ba149
	Issue introduced in 5.10 with commit d98dfad35c38c037b37c4adc99df01da571031a5 and fixed in 6.1.175 with commit 299efd14c2eda7e5fd40025e54addd4151a01081
	Issue introduced in 5.10 with commit d98dfad35c38c037b37c4adc99df01da571031a5 and fixed in 6.6.142 with commit 4d1da9a6be5a8156c532d571c2ed237169f99244
	Issue introduced in 5.10 with commit d98dfad35c38c037b37c4adc99df01da571031a5 and fixed in 6.12.92 with commit b96c7f0bc0713dc6403912f6527d4ff9168d6fe6
	Issue introduced in 5.10 with commit d98dfad35c38c037b37c4adc99df01da571031a5 and fixed in 6.18.34 with commit fa7ca363069a70b0d1aa51e8892e3095fe2ac1ec
	Issue introduced in 5.10 with commit d98dfad35c38c037b37c4adc99df01da571031a5 and fixed in 7.0.11 with commit 2aef8f08c479f4cbc83e1e6b19d1c94d4dd24f17
	Issue introduced in 5.10 with commit d98dfad35c38c037b37c4adc99df01da571031a5 and fixed in 7.1 with commit d7834d92251baade796812876e95555e2066fa9f

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-64084
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	drivers/hwmon/pmbus/adm1266.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/d0593e15fdeb56048a72c5c6e720f702759d0ccd
	https://git.kernel.org/stable/c/17cee2f59029039416e8f6303050038eb59ba149
	https://git.kernel.org/stable/c/299efd14c2eda7e5fd40025e54addd4151a01081
	https://git.kernel.org/stable/c/4d1da9a6be5a8156c532d571c2ed237169f99244
	https://git.kernel.org/stable/c/b96c7f0bc0713dc6403912f6527d4ff9168d6fe6
	https://git.kernel.org/stable/c/fa7ca363069a70b0d1aa51e8892e3095fe2ac1ec
	https://git.kernel.org/stable/c/2aef8f08c479f4cbc83e1e6b19d1c94d4dd24f17
	https://git.kernel.org/stable/c/d7834d92251baade796812876e95555e2066fa9f
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.