CVE-2026-64504: iio: accel: bmc150: clamp the device-reported FIFO frame count

Greg Kroah-Hartman <[email protected]> Sat, 25 Jul 2026 10:52:01 +0200
Newsgroups org.kernel.vger.linux-cve-announce
Message-ID <2026072553-CVE-2026-64504-8f1b@gregkh>
From: Greg Kroah-Hartman <[email protected]>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

iio: accel: bmc150: clamp the device-reported FIFO frame count

__bmc150_accel_fifo_flush() copies the number of samples the device
reports in its hardware FIFO into an on-stack buffer

	u16 buffer[BMC150_ACCEL_FIFO_LENGTH * 3];

which is sized for at most BMC150_ACCEL_FIFO_LENGTH (32) samples. The
frame count is read from the FIFO_STATUS register and only masked to its
7 valid bits:

	count = val & 0x7F;

so it can be 0..127. The only other limit applied to it is the optional
caller-supplied sample budget:

	if (samples && count > samples)
		count = samples;

which does not constrain count on the flush-all path (samples == 0), and
leaves it well above 32 whenever samples is larger. count samples are
then transferred into buffer[]:

	bmc150_accel_fifo_transfer(data, (u8 *)buffer, count);

bmc150_accel_fifo_transfer() reads count * 6 bytes through regmap, so a
malfunctioning, malicious or counterfeit accelerometer (or an attacker
tampering with the I2C/SPI bus) that reports up to 127 frames writes up
to 762 bytes into the 192-byte buffer: a stack out-of-bounds write of up
to 570 bytes that clobbers the stack canary, saved registers and the
return address.

Clamp count to BMC150_ACCEL_FIFO_LENGTH, the number of samples buffer[]
is sized for, before the transfer, mirroring the watermark clamp already
done in bmc150_accel_set_watermark(). A well-formed flush reports at most
BMC150_ACCEL_FIFO_LENGTH frames, so legitimate devices are unaffected.

The Linux kernel CVE team has assigned CVE-2026-64504 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 4.1 with commit 3bbec9773389112330954a6a64422eaa78d546c1 and fixed in 5.10.261 with commit b5a9f521e0a49a0266200fd535b32a9668ecb33b
	Issue introduced in 4.1 with commit 3bbec9773389112330954a6a64422eaa78d546c1 and fixed in 5.15.212 with commit 2fe0531dd73eff1de0f2584cb77716d645e548d5
	Issue introduced in 4.1 with commit 3bbec9773389112330954a6a64422eaa78d546c1 and fixed in 6.1.178 with commit d0e6d924a5484e005cae5aff6a0aa07a22f3c9ff
	Issue introduced in 4.1 with commit 3bbec9773389112330954a6a64422eaa78d546c1 and fixed in 6.6.145 with commit bfffc98f3de92e0f76be7c7b72e63ac1776a6dbc
	Issue introduced in 4.1 with commit 3bbec9773389112330954a6a64422eaa78d546c1 and fixed in 6.12.96 with commit 89f4a4ca0ac3a933c750569a771c079a290b0721
	Issue introduced in 4.1 with commit 3bbec9773389112330954a6a64422eaa78d546c1 and fixed in 6.18.39 with commit 3e766526827acd542bcd36c20c4d5f397e0f6521
	Issue introduced in 4.1 with commit 3bbec9773389112330954a6a64422eaa78d546c1 and fixed in 7.1.4 with commit 35a3cd8fd65e15029eb90f1e510045b1bb071175
	Issue introduced in 4.1 with commit 3bbec9773389112330954a6a64422eaa78d546c1 and fixed in 7.2-rc3 with commit ce0e1cae26096fe959a0da5563a6d6d5a801d5fb

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-64504
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	drivers/iio/accel/bmc150-accel-core.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/b5a9f521e0a49a0266200fd535b32a9668ecb33b
	https://git.kernel.org/stable/c/2fe0531dd73eff1de0f2584cb77716d645e548d5
	https://git.kernel.org/stable/c/d0e6d924a5484e005cae5aff6a0aa07a22f3c9ff
	https://git.kernel.org/stable/c/bfffc98f3de92e0f76be7c7b72e63ac1776a6dbc
	https://git.kernel.org/stable/c/89f4a4ca0ac3a933c750569a771c079a290b0721
	https://git.kernel.org/stable/c/3e766526827acd542bcd36c20c4d5f397e0f6521
	https://git.kernel.org/stable/c/35a3cd8fd65e15029eb90f1e510045b1bb071175
	https://git.kernel.org/stable/c/ce0e1cae26096fe959a0da5563a6d6d5a801d5fb