PT-2026-61284 · Linux+1 · Linux Kernel+1

CVE-2026-63967

·

Published

2026-05-15

·

Updated

2026-09-07

CVSS v2.0

1.7

Low

VectorAV:L/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A stack leak exists in the tagged FIFO buffer of the st lsm6dsx IMU driver. The iio buff structure is declared on the stack with alignment but without an initializer. Due to a hole in the structure, uninitialized memory is leaked to userspace when ST LSM6DSX SAMPLE SIZE bytes are copied, as the space between the sample data and the timestamp remains uninitialized.
Recommendations Zero-initialize the iio buff structure on the stack to prevent memory leakage.

Exploit

Fix

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14314
CVE-2026-63967
OPENSUSE-SU-2026:21555-1
SUSE-SU-2026:23066-1
SUSE-SU-2026:23068-1
SUSE-SU-2026:23193-1
SUSE-SU-2026:23194-1
SUSE-SU-2026:23221-1
SUSE-SU-2026:23231-1
SUSE-SU-2026:23237-1
SUSE-SU-2026:23241-1
SUSE-SU-2026:23244-1
SUSE-SU-2026:3790-1
SUSE-SU-2026:3810-1
USN-8593-1
USN-8603-1
USN-8618-1
USN-8663-1
USN-8664-1
USN-8728-1

Affected Products

Linux Kernel
Ubuntu