Executive brief
A vulnerability was identified in the Linux kernel's support for certain MediaTek hardware components used for measuring electrical signals. If the system fails to read a measurement correctly, it may inadvertently expose internal memory data instead of a valid result. This could allow a local user to potentially access small amounts of sensitive information from the system's memory.
Technical details
A vulnerability exists in the mt6358_read_imp() function within the drivers/iio/adc/mt6359-auxadc.c driver. The function calls regmap_read() but does not verify if the operation succeeded. If the bus read fails, the variable 'val_v' remains uninitialized, and its previous stack contents are returned as a measurement result to userspace. This constitutes an information leak of kernel stack data. The fix involves initializing the variable to zero to ensure predictable behavior during hardware failures. Patches have been backported to various stable kernel branches including 6.12.93, 6.18.35, and 7.0.12.
Affected products
- Linux Linux Kernel 6.11, 6.12, 6.18, 7.0
Timeline
- 2026-07-19: advisory
- 2026-07-19: disclosed
- 2026-06-09: patched