CVE-2026-64084: hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR
Greg Kroah-Hartman <[email protected]>
| Newsgroups | org.kernel.vger.linux-cve-announce |
|---|---|
| Message-ID | <2026071916-CVE-2026-64084-b17b@gregkh> |
From: Greg Kroah-Hartman <[email protected]> Description =========== In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR adm1266_gpio_get_multiple() iterates the PDIO portion of the caller-supplied mask using for_each_set_bit_from(gpio_nr, mask, ADM1266_GPIO_NR + ADM1266_PDIO_STATUS) { ... } where ADM1266_PDIO_STATUS is the PMBus command code (0xE9, i.e. 233), not the number of PDIO pins. The intended upper bound is ADM1266_GPIO_NR + ADM1266_PDIO_NR = 25. gpiolib hands in a mask sized for gc.ngpio (= 25 bits on this chip), so the iteration walks find_next_bit() up to 242, reading up to 217 extra bits (a handful of unsigned-long words: four on 64-bit, seven on 32-bit) of whatever lives past the end of the mask in the caller's stack. Any incidental set bit in that range then drives a set_bit(gpio_nr, bits) call that writes past the end of the caller-supplied bits array too -- both out-of-bounds. Substitute ADM1266_PDIO_NR for the constant so the scan stops at the last real PDIO bit. The Linux kernel CVE team has assigned CVE-2026-64084 to this issue. Affected and fixed versions =========================== Issue introduced in 5.10 with commit d98dfad35c38c037b37c4adc99df01da571031a5 and fixed in 5.10.258 with commit d0593e15fdeb56048a72c5c6e720f702759d0ccd Issue introduced in 5.10 with commit d98dfad35c38c037b37c4adc99df01da571031a5 and fixed in 5.15.209 with commit 17cee2f59029039416e8f6303050038eb59ba149 Issue introduced in 5.10 with commit d98dfad35c38c037b37c4adc99df01da571031a5 and fixed in 6.1.175 with commit 299efd14c2eda7e5fd40025e54addd4151a01081 Issue introduced in 5.10 with commit d98dfad35c38c037b37c4adc99df01da571031a5 and fixed in 6.6.142 with commit 4d1da9a6be5a8156c532d571c2ed237169f99244 Issue introduced in 5.10 with commit d98dfad35c38c037b37c4adc99df01da571031a5 and fixed in 6.12.92 with commit b96c7f0bc0713dc6403912f6527d4ff9168d6fe6 Issue introduced in 5.10 with commit d98dfad35c38c037b37c4adc99df01da571031a5 and fixed in 6.18.34 with commit fa7ca363069a70b0d1aa51e8892e3095fe2ac1ec Issue introduced in 5.10 with commit d98dfad35c38c037b37c4adc99df01da571031a5 and fixed in 7.0.11 with commit 2aef8f08c479f4cbc83e1e6b19d1c94d4dd24f17 Issue introduced in 5.10 with commit d98dfad35c38c037b37c4adc99df01da571031a5 and fixed in 7.1 with commit d7834d92251baade796812876e95555e2066fa9f Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-64084 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/hwmon/pmbus/adm1266.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/d0593e15fdeb56048a72c5c6e720f702759d0ccd https://git.kernel.org/stable/c/17cee2f59029039416e8f6303050038eb59ba149 https://git.kernel.org/stable/c/299efd14c2eda7e5fd40025e54addd4151a01081 https://git.kernel.org/stable/c/4d1da9a6be5a8156c532d571c2ed237169f99244 https://git.kernel.org/stable/c/b96c7f0bc0713dc6403912f6527d4ff9168d6fe6 https://git.kernel.org/stable/c/fa7ca363069a70b0d1aa51e8892e3095fe2ac1ec https://git.kernel.org/stable/c/2aef8f08c479f4cbc83e1e6b19d1c94d4dd24f17 https://git.kernel.org/stable/c/d7834d92251baade796812876e95555e2066fa9f