CVE-2026-64086

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/07/2026
Last modified:
20/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer<br /> <br /> adm1266_pmbus_block_xfer() sets up the read transaction with<br /> <br /> .buf = data-&gt;read_buf,<br /> .len = ADM1266_PMBUS_BLOCK_MAX + 2,<br /> <br /> but read_buf in struct adm1266_data is declared as<br /> <br /> u8 read_buf[ADM1266_PMBUS_BLOCK_MAX + 1];<br /> <br /> For a max-length block response (length byte = 255 + up to 1 PEC<br /> byte), the i2c controller is told to write 257 bytes into a 256-byte<br /> buffer, putting one byte past the end of read_buf. The same response<br /> also makes the subsequent PEC compare<br /> <br /> if (crc != msgs[1].buf[msgs[1].buf[0] + 1])<br /> <br /> read a byte beyond the array.<br /> <br /> Bump the read_buf declaration to ADM1266_PMBUS_BLOCK_MAX + 2 so the<br /> buffer can hold the length byte, up to 255 payload bytes, and the PEC<br /> byte the i2c_msg length already accounts for.