Executive brief
A vulnerability in the Linux kernel's BMP580 pressure sensor driver could allow a local user to view small amounts of sensitive information from the system's memory. This occurs because the driver fails to clear temporary storage before sending sensor data to applications, inadvertently including leftover data from the system stack. While the amount of data leaked per request is small, it could potentially expose internal system details to an unauthorized observer.
Technical details
A stack information leak exists in the bmp580_trigger_handler() function within the drivers/iio/pressure/bmp280-core.c component of the Linux kernel. The vulnerability is caused by the scan buffer being declared on the stack without initialization. Because the driver only copies 3 bytes of 24-bit sensor data into 4-byte fields, the high byte of the temperature and pressure fields remains uninitialized. When this data is pushed to userspace, two bytes of uninitialized stack memory are leaked per scan. This issue was a regression introduced when the buffer was moved from private data to a stack-local structure. The fix involves zero-initializing the buffer structure on the stack.
Affected products
- Linux Linux Kernel 6.16 to 7.1
Timeline
- 2026-07-19: disclosed
- 2026-07-19: advisory