Junglewise Threat Intelligence

CVE-2026-64497: Linux Kernel sign-extension bug in SCD30 chemical sensor driver

CVE-2026-64497 · Severity: info · CVSS 0 · Published 2026-07-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A bug was identified in the Linux kernel driver for the SCD30 carbon dioxide sensor. The issue involves a technical error in how the software processes numerical data from the sensor, which could lead to incorrect readings or unexpected behavior in systems relying on this hardware. This has been resolved in recent kernel updates.

Technical details

A sign-extension vulnerability was identified in `drivers/iio/chemical/scd30_core.c` within the `scd30_float_to_fp` function. The root cause was an incorrect bitwise operation where a 32-bit float value was ANDed with `~BIT(31)`, resulting in a 64-bit mask (0xFFFFFFFF7FFFFFFF) on 64-bit architectures due to sign extension. This mask corrupted the exponent bits of the sensor data. The fix involves refactoring the initialization using `FIELD_GET()` from `linux/bitfield.h` to properly isolate the mantissa, exponent, and sign bits. The vulnerability affects Linux kernel versions starting from 5.9.

Affected products

  • Linux Linux Kernel 5.9 to 6.10.y

Timeline

  • 2026-05-26: disclosed: Patch submitted by Maxwell Doose
  • 2026-07-24: patched: Committed to stable kernel tree
  • 2026-07-25: advisory: CVE-2026-64497 published

References

Related threats