CVE-2026-64084
CVE CVE-2026-64084EUVD EUVD-2026-45657Published 2026-07-19T15:39:55.000ZLast changed 2026-08-05T12:39:02.000ZCVSS 7.8
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR adm1266_gpio_get_multiple() iterates the PDIO portion of the caller-supplied mask using for_each_set_bit_from(gpio_nr, mask, ADM1266_GPIO_NR + ADM1266_PDIO_STATUS) { ... } where ADM1266_PDIO_STATUS is the PMBus command code (0xE9, i.e. 233), not the number of PDIO pins. The intended upper bound is ADM1266_GPIO_NR + ADM1266_PDIO_NR = 25. gpiolib hands in a mask sized for gc.ngpio (= 25 bits on this chip), so the iteration walks find_next_bit() up to 242, reading up to 217 extra bits (a handful of unsigned-long words: four on 64-bit, seven on 32-bit) of whatever lives past the end of the mask in the caller's stack. Any incidental set bit in that range then drives a set_bit(gpio_nr, bits) call that writes past the end of the caller-supplied bits array too -- both out-of-bounds. Substitute ADM1266_PDIO_NR for the constant so the scan stops at the last real PDIO bit.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 7.1; d98dfad35c38c037b37c4adc99df01da571031a5 <2aef8f08c479f4cbc83e1e6b19d1c94d4dd24f17; patch: 6.6.142; patch: 0; d98dfad35c38c037b37c4adc99df01da571031a5 <17cee2f59029039416e8f6303050038eb59ba149; d98dfad35c38c037b37c4adc99df01da571031a5 <fa7ca363069a70b0d1aa51e8892e3095fe2ac1ec; patch: 6.1.175; patch: 6.12.92; patch: 5.10.258; 5.10; d98dfad35c38c037b37c4adc99df01da571031a5 <b96c7f0bc0713dc6403912f6527d4ff9168d6fe6; d98dfad35c38c037b37c4adc99df01da571031a5 <d7834d92251baade796812876e95555e2066fa9f; d98dfad35c38c037b37c4adc99df01da571031a5 <4d1da9a6be5a8156c532d571c2ed237169f99244; patch: 7.0.11; patch: 5.15.209; d98dfad35c38c037b37c4adc99df01da571031a5 <d0593e15fdeb56048a72c5c6e720f702759d0ccd; patch: 6.18.34; d98dfad35c38c037b37c4adc99df01da571031a5 <299efd14c2eda7e5fd40025e54addd4151a01081
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.