CVE-2026-72481

Source
https://cve.org/CVERecord?id=CVE-2026-72481
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72481.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72481
Downstream
Published
2026-08-15T05:57:19.613Z
Modified
2026-08-18T03:31:01.751334823Z
Summary
iio: magnetometer: ak8975: fix potential kernel stack memory leak
Details

In the Linux kernel, the following vulnerability has been resolved:

iio: magnetometer: ak8975: fix potential kernel stack memory leak

Currently in the AK8975 driver there are four instances where potential uninitialized kernel stack memory leaks can occur. If i2csmbusreadi2cblockdataor_emulated() returns a value less than the size of the buffer, uninitialized bytes are retained in the buffer and later the buffer is passed on to IIO buffers, potentially leaking memory to userspace.

Fix this by adding checks whether the return value of the function is equal to the size of the buffer and subsequently if the value is lesser than zero to distinguish from a returned error code.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72481.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
bc11ca4a0b84a2f2ebaca2614b92998738d13b1e
Fixed
12848f4ded022963944c063e09a192549a4dad1e
Fixed
a9cf46054f81972f8c0f1dc2a79d2a141999dbce
Fixed
9f920550abacedc7fc3163dea65ac2a7d0b0765d
Fixed
8cf346074533356d67a6a6a43a192328ad341f11
Fixed
b974566803bceb72f0b9b5f1d7270b79ba963766
Fixed
3d57672119525c59ed73ea21accb001ccbcd6cfd
Fixed
fb27ebf81136e796c7b719303ef6fd7e1ae5d488
Fixed
a9a00d727b7bbc5e913a919530a9dd468935bf95

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72481.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.7.0
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72481.json"