CVE-2026-64084

Source
https://cve.org/CVERecord?id=CVE-2026-64084
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64084.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64084
Downstream
Published
2026-07-19T15:39:55.417Z
Modified
2026-07-22T05:29:47.875356117Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR
Details

In the Linux kernel, the following vulnerability has been resolved:

hwmon: (pmbus/adm1266) cap PDIO scan in getmultiple at ADM1266PDIO_NR

adm1266gpioget_multiple() iterates the PDIO portion of the caller-supplied mask using

for_each_set_bit_from(gpio_nr, mask,
              ADM1266_GPIO_NR + ADM1266_PDIO_STATUS) {
    ...
}

where ADM1266PDIOSTATUS is the PMBus command code (0xE9, i.e. 233), not the number of PDIO pins. The intended upper bound is ADM1266GPIONR + ADM1266PDIONR = 25.

gpiolib hands in a mask sized for gc.ngpio (= 25 bits on this chip), so the iteration walks findnextbit() up to 242, reading up to 217 extra bits (a handful of unsigned-long words: four on 64-bit, seven on 32-bit) of whatever lives past the end of the mask in the caller's stack. Any incidental set bit in that range then drives a setbit(gpionr, bits) call that writes past the end of the caller-supplied bits array too -- both out-of-bounds.

Substitute ADM1266PDIONR for the constant so the scan stops at the last real PDIO bit.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64084.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
d98dfad35c38c037b37c4adc99df01da571031a5
Fixed
d0593e15fdeb56048a72c5c6e720f702759d0ccd
Fixed
17cee2f59029039416e8f6303050038eb59ba149
Fixed
299efd14c2eda7e5fd40025e54addd4151a01081
Fixed
4d1da9a6be5a8156c532d571c2ed237169f99244
Fixed
b96c7f0bc0713dc6403912f6527d4ff9168d6fe6
Fixed
fa7ca363069a70b0d1aa51e8892e3095fe2ac1ec
Fixed
2aef8f08c479f4cbc83e1e6b19d1c94d4dd24f17
Fixed
d7834d92251baade796812876e95555e2066fa9f

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64084.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.10.0
Fixed
5.10.258
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.209
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.175
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.142
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.92
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.34
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.11

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64084.json"