Executive brief
A vulnerability in the Linux kernel's hardware monitoring driver for ADM1266 devices could allow an attacker or a malfunctioning device to leak sensitive information from the system's memory. By providing an unexpectedly short data response during hardware status checks, the system may inadvertently expose internal kernel data to user-level applications. This could potentially be used to bypass security protections or gain insight into private system operations.
Technical details
A vulnerability exists in the adm1266_gpio_get() and adm1266_gpio_get_multiple() functions within the drivers/hwmon/pmbus/adm1266.c component of the Linux kernel. The driver fails to verify that i2c_smbus_read_block_data() returns the expected 2 bytes of data before processing the buffer. If a device or a malicious actor on the I2C bus returns 0 or 1 byte, the driver uses uninitialized stack memory to compose the GPIO status word. This uninitialized data is subsequently returned to userspace via gpiolib (sysfs or char-dev ioctls), resulting in a kernel stack information leak. The issue has been resolved by adding explicit length checks that return -EIO for short responses.
Affected products
- Linux Linux d98dfad35c38 to fd9196aad9e5, d98dfad35c38 to ee4799becf7d, d98dfad35c38 to c603b6c6840a, d98dfad35c38 to a2d1c819348b, d98dfad35c38 to ae25cf2ea9ebd, d98dfad35c38 to eb3cd9bb5904, d98dfad35c38 to 64fa9328948d
Timeline
- 2026-05-18: disclosed: Initial patch submitted by Abdurrahman Hussain
- 2026-07-19: advisory: CVE-2026-64083 published
References
- https://git.kernel.org/stable/c/64fa9328948ddcc0f7f3c23ea1756c126d9dffac
- https://git.kernel.org/stable/c/a2d1c819348b36fccbbfcf37c5fa7a50a9b4528f
- https://git.kernel.org/stable/c/a7232f68c43ca62f545049b7f5fbfc75137b843b
- https://git.kernel.org/stable/c/ae25cf2ea9ebd06d7ad416647dbdc7b5d0172946
- https://git.kernel.org/stable/c/c603b6c6840ac0c6285f5eefea0de6242710af21
- https://git.kernel.org/stable/c/eb3cd9bb590460c6127145cb245be925d23f5232
- https://git.kernel.org/stable/c/ee4799becf7d2af3778007e22c2e55c4009a49c7