Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
CVE-2026-64087: Linux Kernel: Malformed Sensor Data Can Crash System
CVE-2026-64087
CVE-2026-64087
Summary
A security issue was fixed in the Linux kernel that could cause a system crash if a sensor device reports incorrect data. This issue is now resolved, but it's essential to keep your Linux kernel up to date to prevent potential problems. If you're using a Linux system, ensure you're running the latest version of the kernel to stay secure.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| linux | linux |
< adcb163ad7cacca317872fc62bd8885e842e45e3 5.10 |
Original title
In the Linux kernel, the following vulnerability has been resolved:
hwmon: (pmbus/adm1266) reject implausible blackbox record_count
adm1266_nvmem_read_blackbox() loops over a record_count that co...
Original description
In the Linux kernel, the following vulnerability has been resolved:
hwmon: (pmbus/adm1266) reject implausible blackbox record_count
adm1266_nvmem_read_blackbox() loops over a record_count that comes
straight from byte 3 of the BLACKBOX_INFO response. The destination
buffer is data->dev_mem, sized for the nvmem cell's declared 2048
bytes (ADM1266_BLACKBOX_MAX_RECORDS * ADM1266_BLACKBOX_SIZE = 32 * 64).
A device that reports a record_count greater than 32 -- whether due
to firmware bugs, bus corruption, or a non-responsive slave returning
0xff -- would walk read_buff past the end of the dev_mem allocation
on the trailing iterations.
Cap record_count at ADM1266_BLACKBOX_MAX_RECORDS (introduced here)
before entering the loop and return -EIO on any larger value, so a
malformed BLACKBOX_INFO response cannot drive the loop out of bounds.
hwmon: (pmbus/adm1266) reject implausible blackbox record_count
adm1266_nvmem_read_blackbox() loops over a record_count that comes
straight from byte 3 of the BLACKBOX_INFO response. The destination
buffer is data->dev_mem, sized for the nvmem cell's declared 2048
bytes (ADM1266_BLACKBOX_MAX_RECORDS * ADM1266_BLACKBOX_SIZE = 32 * 64).
A device that reports a record_count greater than 32 -- whether due
to firmware bugs, bus corruption, or a non-responsive slave returning
0xff -- would walk read_buff past the end of the dev_mem allocation
on the trailing iterations.
Cap record_count at ADM1266_BLACKBOX_MAX_RECORDS (introduced here)
before entering the loop and return -EIO on any larger value, so a
malformed BLACKBOX_INFO response cannot drive the loop out of bounds.
- https://git.kernel.org/stable/c/adcb163ad7cacca317872fc62bd8885e842e45e3
- https://git.kernel.org/stable/c/c2c56092710fe8a893b67b5a3d7e62808d02d84d
- https://git.kernel.org/stable/c/5469e1e7c411acc15fdd8262c99c3ebd9defd594
- https://git.kernel.org/stable/c/f85c81e93dbd6915970bd5f3bffcf62633c4c54c
- https://git.kernel.org/stable/c/0e791cd0140fb136083565aadfbe0f705aa260d0
- https://git.kernel.org/stable/c/75c862adf3d3caab4f49bb3530723c215376e37c
- https://git.kernel.org/stable/c/231db52a5b64d0a9769e298dadc148e1f79b26a6
- https://git.kernel.org/stable/c/4afca954622d672ea65ed961bed01cf91caa034e
Published: 19 Jul 2026 · Updated: 20 Jul 2026 · First seen: 19 Jul 2026