{"id":"CVE-2026-64087","summary":"hwmon: (pmbus/adm1266) reject implausible blackbox record_count","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (pmbus/adm1266) reject implausible blackbox record_count\n\nadm1266_nvmem_read_blackbox() loops over a record_count that comes\nstraight from byte 3 of the BLACKBOX_INFO response.  The destination\nbuffer is data-\u003edev_mem, sized for the nvmem cell's declared 2048\nbytes (ADM1266_BLACKBOX_MAX_RECORDS * ADM1266_BLACKBOX_SIZE = 32 * 64).\nA device that reports a record_count greater than 32 -- whether due\nto firmware bugs, bus corruption, or a non-responsive slave returning\n0xff -- would walk read_buff past the end of the dev_mem allocation\non the trailing iterations.\n\nCap record_count at ADM1266_BLACKBOX_MAX_RECORDS (introduced here)\nbefore entering the loop and return -EIO on any larger value, so a\nmalformed BLACKBOX_INFO response cannot drive the loop out of bounds.","modified":"2026-07-21T03:47:53.594349734Z","published":"2026-07-19T15:39:57.371Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64087.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/0e791cd0140fb136083565aadfbe0f705aa260d0"},{"type":"WEB","url":"https://git.kernel.org/stable/c/231db52a5b64d0a9769e298dadc148e1f79b26a6"},{"type":"WEB","url":"https://git.kernel.org/stable/c/4afca954622d672ea65ed961bed01cf91caa034e"},{"type":"WEB","url":"https://git.kernel.org/stable/c/5469e1e7c411acc15fdd8262c99c3ebd9defd594"},{"type":"WEB","url":"https://git.kernel.org/stable/c/75c862adf3d3caab4f49bb3530723c215376e37c"},{"type":"WEB","url":"https://git.kernel.org/stable/c/adcb163ad7cacca317872fc62bd8885e842e45e3"},{"type":"WEB","url":"https://git.kernel.org/stable/c/c2c56092710fe8a893b67b5a3d7e62808d02d84d"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f85c81e93dbd6915970bd5f3bffcf62633c4c54c"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64087.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64087"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"15609d1893020436e1e8ccfd9ded774a96dd17a2"},{"fixed":"adcb163ad7cacca317872fc62bd8885e842e45e3"},{"fixed":"c2c56092710fe8a893b67b5a3d7e62808d02d84d"},{"fixed":"5469e1e7c411acc15fdd8262c99c3ebd9defd594"},{"fixed":"f85c81e93dbd6915970bd5f3bffcf62633c4c54c"},{"fixed":"0e791cd0140fb136083565aadfbe0f705aa260d0"},{"fixed":"75c862adf3d3caab4f49bb3530723c215376e37c"},{"fixed":"231db52a5b64d0a9769e298dadc148e1f79b26a6"},{"fixed":"4afca954622d672ea65ed961bed01cf91caa034e"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64087.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.10.0"},{"fixed":"5.10.258"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.209"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.175"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.142"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.92"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.34"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.0.11"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64087.json"}}],"schema_version":"1.7.5"}