{"id":"CVE-2026-64084","summary":"hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR\n\nadm1266_gpio_get_multiple() iterates the PDIO portion of the\ncaller-supplied mask using\n\n\tfor_each_set_bit_from(gpio_nr, mask,\n\t\t\t      ADM1266_GPIO_NR + ADM1266_PDIO_STATUS) {\n\t\t...\n\t}\n\nwhere ADM1266_PDIO_STATUS is the PMBus command code (0xE9, i.e. 233),\nnot the number of PDIO pins.  The intended upper bound is\nADM1266_GPIO_NR + ADM1266_PDIO_NR = 25.\n\ngpiolib hands in a mask sized for gc.ngpio (= 25 bits on this chip),\nso the iteration walks find_next_bit() up to 242, reading up to 217\nextra bits (a handful of unsigned-long words: four on 64-bit, seven\non 32-bit) of whatever lives past the end of the mask in the\ncaller's stack.  Any incidental set bit in that range then drives a\nset_bit(gpio_nr, bits) call that writes past the end of the\ncaller-supplied bits array too -- both out-of-bounds.\n\nSubstitute ADM1266_PDIO_NR for the constant so the scan stops at the\nlast real PDIO bit.","modified":"2026-07-22T05:29:47.875356117Z","published":"2026-07-19T15:39:55.417Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64084.json","cna_assigner":"Linux"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/17cee2f59029039416e8f6303050038eb59ba149"},{"type":"WEB","url":"https://git.kernel.org/stable/c/299efd14c2eda7e5fd40025e54addd4151a01081"},{"type":"WEB","url":"https://git.kernel.org/stable/c/2aef8f08c479f4cbc83e1e6b19d1c94d4dd24f17"},{"type":"WEB","url":"https://git.kernel.org/stable/c/4d1da9a6be5a8156c532d571c2ed237169f99244"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b96c7f0bc0713dc6403912f6527d4ff9168d6fe6"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d0593e15fdeb56048a72c5c6e720f702759d0ccd"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d7834d92251baade796812876e95555e2066fa9f"},{"type":"WEB","url":"https://git.kernel.org/stable/c/fa7ca363069a70b0d1aa51e8892e3095fe2ac1ec"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64084.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64084"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"d98dfad35c38c037b37c4adc99df01da571031a5"},{"fixed":"d0593e15fdeb56048a72c5c6e720f702759d0ccd"},{"fixed":"17cee2f59029039416e8f6303050038eb59ba149"},{"fixed":"299efd14c2eda7e5fd40025e54addd4151a01081"},{"fixed":"4d1da9a6be5a8156c532d571c2ed237169f99244"},{"fixed":"b96c7f0bc0713dc6403912f6527d4ff9168d6fe6"},{"fixed":"fa7ca363069a70b0d1aa51e8892e3095fe2ac1ec"},{"fixed":"2aef8f08c479f4cbc83e1e6b19d1c94d4dd24f17"},{"fixed":"d7834d92251baade796812876e95555e2066fa9f"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64084.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.10.0"},{"fixed":"5.10.258"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.209"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.175"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.142"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.92"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.34"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.0.11"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64084.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}