Executive brief
A flaw in the Linux kernel driver for the ITG3200 gyroscope sensor could allow a local user to view sensitive information from the system's memory. Instead of providing actual sensor data like rotation or temperature, the system may inadvertently leak internal memory contents to applications. This primarily affects devices using this specific hardware sensor and could lead to the exposure of private system data.
Technical details
A vulnerability in the ITG3200 gyroscope driver (drivers/iio/gyro/itg3200_buffer.c) stems from an incorrect pointer dereference in itg3200_read_all_channels(). The function incorrectly used the address of a pointer (&buf) instead of the pointer itself (buf) as the destination for an I2C read operation. Consequently, i2c_transfer() writes 8 bytes of data into the local stack slot of the pointer rather than the intended caller-provided buffer. When the driver subsequently pushes data to userspace via iio_push_to_buffers_with_timestamp(), it transmits uninitialized stack memory instead of sensor data. This results in a functional failure of the sensor and a kernel information leak to any local process with access to the IIO device node.
Affected products
- Linux Linux Kernel 9dbf091da080 to 6bdc3023d62e
Timeline
- 2026-05-05: other: Vulnerability fixed in source code by David Carlier
- 2026-07-19: disclosed: CVE published
References
- https://git.kernel.org/stable/c/15a0b3f33ffb6c78b3de6f69b026ceb09b973dd1
- https://git.kernel.org/stable/c/31bbd4b87dd6701fa10e03ba7f6268e49e178d16
- https://git.kernel.org/stable/c/63203bd072b613c18c237b906b1c9d2dc4527337
- https://git.kernel.org/stable/c/6bdc3023d62ed5c7d591f0eb27a5adb37fb892ae
- https://git.kernel.org/stable/c/8654b5e2617819ff4f7c78071dfd0275e971a9b6
- https://git.kernel.org/stable/c/90e809376b0f0d1ddec2eec954aecdd2a5b40b0e
- https://git.kernel.org/stable/c/b64dd5f3b38911054cbcc570df617e3e8e75e562