CVE-2026-72479

Source
https://cve.org/CVERecord?id=CVE-2026-72479
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72479.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72479
Downstream
Published
2026-08-15T05:57:18.324Z
Modified
2026-08-18T03:31:15.651369248Z
Summary
iio: accel: mma8452: handle I2C read error(s) in mma8452_read()
Details

In the Linux kernel, the following vulnerability has been resolved:

iio: accel: mma8452: handle I2C read error(s) in mma8452_read()

Currently, If i2csmbusreadi2cblockdata() fails but mma8452setruntimepmstate() succeeds, mma8452read() returns 0.

As a result, the caller mma8452readraw() assumes the read was successful and proceeds to use a buffer containing uninitialized stack memory.

Add proper checking of the I2C read return value and propagate errors to the caller.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72479.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
96c0cb2bbfe0a58bd0c37cf34d50a20f9cd75aa8
Fixed
b488055e81d9faaaf2f8aaff45f9944040ac4493
Fixed
f9ec3f3e9cf27dd06cd3725eeaa44e3ce46be893
Fixed
b4932fc325e84a3233413daf230b043818c8a824
Fixed
eed69f8a10b82989ad732ace0fb43a9fb4e7fe35
Fixed
f3d905ea1e4996d933074481e80d96ecd74a9904
Fixed
1cddef80a180af74c33d2f26c962ce92b60fded4
Fixed
f3d413e701c5e54bef736b638967724dda880365
Fixed
5bdff291d20c31b365d9ddfe9c426fbfb41da5bb

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72479.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.7.0
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72479.json"