CVE-2026-64087
CVE CVE-2026-64087EUVD EUVD-2026-45772Published 2026-07-19T15:39:57.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus/adm1266) reject implausible blackbox record_count adm1266_nvmem_read_blackbox() loops over a record_count that comes straight from byte 3 of the BLACKBOX_INFO response. The destination buffer is data->dev_mem, sized for the nvmem cell's declared 2048 bytes (ADM1266_BLACKBOX_MAX_RECORDS * ADM1266_BLACKBOX_SIZE = 32 * 64). A device that reports a record_count greater than 32 -- whether due to firmware bugs, bus corruption, or a non-responsive slave returning 0xff -- would walk read_buff past the end of the dev_mem allocation on the trailing iterations. Cap record_count at ADM1266_BLACKBOX_MAX_RECORDS (introduced here) before entering the loop and return -EIO on any larger value, so a malformed BLACKBOX_INFO response cannot drive the loop out of bounds.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 6.18.34; patch: 5.15.209; patch: 0; patch: 7.0.11; 15609d1893020436e1e8ccfd9ded774a96dd17a2 <adcb163ad7cacca317872fc62bd8885e842e45e3; 5.10; 15609d1893020436e1e8ccfd9ded774a96dd17a2 <75c862adf3d3caab4f49bb3530723c215376e37c; patch: 5.10.258; patch: 6.6.142; patch: 7.1; 15609d1893020436e1e8ccfd9ded774a96dd17a2 <f85c81e93dbd6915970bd5f3bffcf62633c4c54c; 15609d1893020436e1e8ccfd9ded774a96dd17a2 <4afca954622d672ea65ed961bed01cf91caa034e; 15609d1893020436e1e8ccfd9ded774a96dd17a2 <c2c56092710fe8a893b67b5a3d7e62808d02d84d; patch: 6.12.92; patch: 6.1.175; 15609d1893020436e1e8ccfd9ded774a96dd17a2 <231db52a5b64d0a9769e298dadc148e1f79b26a6; 15609d1893020436e1e8ccfd9ded774a96dd17a2 <5469e1e7c411acc15fdd8262c99c3ebd9defd594; 15609d1893020436e1e8ccfd9ded774a96dd17a2 <0e791cd0140fb136083565aadfbe0f705aa260d0
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.