CVE-2026-64495: iio: gyro: bmg160: bail out when bandwidth/filter is not in table
Greg Kroah-Hartman <[email protected]> Sat, 25 Jul 2026 10:51:52 +0200
| Newsgroups | org.kernel.vger.linux-cve-announce |
|---|---|
| Message-ID | <2026072551-CVE-2026-64495-38ea@gregkh> |
From: Greg Kroah-Hartman <[email protected]> Description =========== In the Linux kernel, the following vulnerability has been resolved: iio: gyro: bmg160: bail out when bandwidth/filter is not in table bmg160_get_filter() walks bmg160_samp_freq_table[] looking for the entry matching the bw_bits value read from the chip: for (i = 0; i < ARRAY_SIZE(bmg160_samp_freq_table); ++i) { if (bmg160_samp_freq_table[i].bw_bits == bw_bits) break; } *val = bmg160_samp_freq_table[i].filter; If no entry matches, i ends up equal to the array size and the next line reads one slot past the end. bmg160_set_filter() has the same shape, driven by 'val' instead of bw_bits. smatch flags both: drivers/iio/gyro/bmg160_core.c:204 bmg160_get_filter() error: buffer overflow 'bmg160_samp_freq_table' 7 <= 7 drivers/iio/gyro/bmg160_core.c:222 bmg160_set_filter() error: buffer overflow 'bmg160_samp_freq_table' 7 <= 7 Return -EINVAL when no entry matches. The set_filter() path is reachable from userspace via the sysfs in_anglvel_filter_low_pass_3db_frequency interface, so userspace can trivially trigger the out-of-bounds read with a value that is not in bmg160_samp_freq_table[].filter. The Linux kernel CVE team has assigned CVE-2026-64495 to this issue. Affected and fixed versions =========================== Issue introduced in 3.18 with commit 22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc and fixed in 5.10.261 with commit 1dc3a833be11e5d503038e3c701745fd0e03903c Issue introduced in 3.18 with commit 22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc and fixed in 5.15.212 with commit 77e56ebb1786f4296afd5fa46975a989b285ae65 Issue introduced in 3.18 with commit 22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc and fixed in 6.1.178 with commit 029481cddb98697716f4bf3021d035eaf2ca0e1f Issue introduced in 3.18 with commit 22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc and fixed in 6.6.145 with commit 8d202515baea4e2e3be448d1590099af28f2346d Issue introduced in 3.18 with commit 22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc and fixed in 6.12.96 with commit d85ee50f58dd83fe74f6d0bf8bd345c657b216e8 Issue introduced in 3.18 with commit 22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc and fixed in 6.18.39 with commit 7bbf02b63961fc1768c9c654392c11f2077d4c59 Issue introduced in 3.18 with commit 22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc and fixed in 7.1.4 with commit 6c8675468862161d1c59130266852b66867d3861 Issue introduced in 3.18 with commit 22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc and fixed in 7.2-rc1 with commit 8320c77e67382d5d55d77043a5f60a867d408a2b Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-64495 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/iio/gyro/bmg160_core.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/1dc3a833be11e5d503038e3c701745fd0e03903c https://git.kernel.org/stable/c/77e56ebb1786f4296afd5fa46975a989b285ae65 https://git.kernel.org/stable/c/029481cddb98697716f4bf3021d035eaf2ca0e1f https://git.kernel.org/stable/c/8d202515baea4e2e3be448d1590099af28f2346d https://git.kernel.org/stable/c/d85ee50f58dd83fe74f6d0bf8bd345c657b216e8 https://git.kernel.org/stable/c/7bbf02b63961fc1768c9c654392c11f2077d4c59 https://git.kernel.org/stable/c/6c8675468862161d1c59130266852b66867d3861 https://git.kernel.org/stable/c/8320c77e67382d5d55d77043a5f60a867d408a2b