PT-2026-61402 · Linux+2 · Linux Kernel+2
CVE-2026-64085
·
Published
2026-07-19
·
Updated
2026-09-07
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the
hwmon subsystem where the adm1266 pmbus block xfer() function copies a device-supplied block payload into a caller-provided buffer using a length specified by the device. The adm1266 nvmem read blackbox() function violates the expected contract by advancing the read buff within the dev mem allocation in 64-byte strides, while the helper function can write up to 255 bytes. A malicious or malfunctioning device returning more than 64 bytes on the trailing record can cause a buffer overflow in dev mem by up to 191 bytes.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Linux Kernel
Ubuntu