Executive brief
A vulnerability was identified in the Linux kernel's driver for the VEML6075 light sensor. Under certain conditions, such as hardware faults or bus corruption, the system could attempt to access memory outside of its intended boundaries. This could lead to system instability or crashes, though it primarily serves as a hardening measure against malfunctioning hardware.
Technical details
An out-of-bounds array access vulnerability existed in the veml6075_it_ms index within the VEML6075 light sensor driver (drivers/iio/light/veml6075.c). The VEML6075_CONF_IT field can return values between 0 and 7, while the corresponding veml6075_it_ms array only contains 5 elements. If a value of 5 or greater is read from the register—which could occur due to hardware faults, bus corruption, or misprogramming—the driver would perform an out-of-bounds read. The fix introduces a bounds check using ARRAY_SIZE and returns -EINVAL if the index is out of range. This is primarily a hardening fix for the Industrial I/O (IIO) subsystem.
Affected products
- Linux Linux 6.12.95, 6.18.37, 7.0.14, 7.1.2, 7.2-rc1
Timeline
- 2026-05-14: other: Patch authored
- 2026-07-19: advisory: CVE published
References
- https://git.kernel.org/stable/c/0a89002737ee34decc20fa232204dbe5fe83e0de
- https://git.kernel.org/stable/c/307dc4240bd41852d9e0912921e298160db1c109
- https://git.kernel.org/stable/c/df9127a1d2d748e426c49c8fcd9b6801e4eb743d
- https://git.kernel.org/stable/c/e545936e06f1c7173ab41a5f33a77ff43ced3a8d
- https://git.kernel.org/stable/c/f75beebcd5bc9bdc80e0722142e78a6f306214ee