CVE-2026-64504
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
25/07/2026
Última modificación:
25/07/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
iio: accel: bmc150: clamp the device-reported FIFO frame count<br />
<br />
__bmc150_accel_fifo_flush() copies the number of samples the device<br />
reports in its hardware FIFO into an on-stack buffer<br />
<br />
u16 buffer[BMC150_ACCEL_FIFO_LENGTH * 3];<br />
<br />
which is sized for at most BMC150_ACCEL_FIFO_LENGTH (32) samples. The<br />
frame count is read from the FIFO_STATUS register and only masked to its<br />
7 valid bits:<br />
<br />
count = val & 0x7F;<br />
<br />
so it can be 0..127. The only other limit applied to it is the optional<br />
caller-supplied sample budget:<br />
<br />
if (samples && count > samples)<br />
count = samples;<br />
<br />
which does not constrain count on the flush-all path (samples == 0), and<br />
leaves it well above 32 whenever samples is larger. count samples are<br />
then transferred into buffer[]:<br />
<br />
bmc150_accel_fifo_transfer(data, (u8 *)buffer, count);<br />
<br />
bmc150_accel_fifo_transfer() reads count * 6 bytes through regmap, so a<br />
malfunctioning, malicious or counterfeit accelerometer (or an attacker<br />
tampering with the I2C/SPI bus) that reports up to 127 frames writes up<br />
to 762 bytes into the 192-byte buffer: a stack out-of-bounds write of up<br />
to 570 bytes that clobbers the stack canary, saved registers and the<br />
return address.<br />
<br />
Clamp count to BMC150_ACCEL_FIFO_LENGTH, the number of samples buffer[]<br />
is sized for, before the transfer, mirroring the watermark clamp already<br />
done in bmc150_accel_set_watermark(). A well-formed flush reports at most<br />
BMC150_ACCEL_FIFO_LENGTH frames, so legitimate devices are unaffected.
Impacto
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/2fe0531dd73eff1de0f2584cb77716d645e548d5
- https://git.kernel.org/stable/c/35a3cd8fd65e15029eb90f1e510045b1bb071175
- https://git.kernel.org/stable/c/3e766526827acd542bcd36c20c4d5f397e0f6521
- https://git.kernel.org/stable/c/89f4a4ca0ac3a933c750569a771c079a290b0721
- https://git.kernel.org/stable/c/b5a9f521e0a49a0266200fd535b32a9668ecb33b
- https://git.kernel.org/stable/c/bfffc98f3de92e0f76be7c7b72e63ac1776a6dbc
- https://git.kernel.org/stable/c/ce0e1cae26096fe959a0da5563a6d6d5a801d5fb
- https://git.kernel.org/stable/c/d0e6d924a5484e005cae5aff6a0aa07a22f3c9ff



