Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-64084

Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
19/07/2026
Última modificación:
20/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR<br /> <br /> adm1266_gpio_get_multiple() iterates the PDIO portion of the<br /> caller-supplied mask using<br /> <br /> for_each_set_bit_from(gpio_nr, mask,<br /> ADM1266_GPIO_NR + ADM1266_PDIO_STATUS) {<br /> ...<br /> }<br /> <br /> where ADM1266_PDIO_STATUS is the PMBus command code (0xE9, i.e. 233),<br /> not the number of PDIO pins. The intended upper bound is<br /> ADM1266_GPIO_NR + ADM1266_PDIO_NR = 25.<br /> <br /> gpiolib hands in a mask sized for gc.ngpio (= 25 bits on this chip),<br /> so the iteration walks find_next_bit() up to 242, reading up to 217<br /> extra bits (a handful of unsigned-long words: four on 64-bit, seven<br /> on 32-bit) of whatever lives past the end of the mask in the<br /> caller&amp;#39;s stack. Any incidental set bit in that range then drives a<br /> set_bit(gpio_nr, bits) call that writes past the end of the<br /> caller-supplied bits array too -- both out-of-bounds.<br /> <br /> Substitute ADM1266_PDIO_NR for the constant so the scan stops at the<br /> last real PDIO bit.