« Volver al listado

CVE-2026-63934

Estado: Pendiente de análisisSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

iio: gyro: itg3200: fix i2c read into the wrong stack location

itg3200_read_all_channels() takes `__be16 *buf' as a parameter and fills the i2c_msg destination as `(char *)&buf'. Since `buf' is the parameter (a pointer), `&buf' is the address of the local pointer slot on the stack of itg3200_read_all_channels(), not the address of the caller's scan buffer. The (char *) cast hides the type mismatch.

i2c_transfer() therefore writes ITG3200_SCAN_ELEMENTS * sizeof(s16) = 8 bytes into the parameter's stack slot, which is discarded when the function returns.

Leer descripción completaMostrar menos

The caller's scan buffer in itg3200_trigger_handler() is never written to, so iio_push_to_buffers_with_timestamp() pushes uninitialised stack contents to userspace via /dev/iio:deviceX every scan -- both a functional bug (no actual gyroscope or temperature data is delivered through the triggered buffer) and an information leak.

The non-buffered read_raw() path is unaffected: it goes through itg3200_read_reg_s16() which uses `&out' on a local s16 value, where that is correct.

Drop the spurious `&' so the i2c read writes into the caller's buffer.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-63934",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "9dbf091da080508e9f632d307f357beb79a0766b",
              "lessThan": "90e809376b0f0d1ddec2eec954aecdd2a5b40b0e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9dbf091da080508e9f632d307f357beb79a0766b",
              "lessThan": "8654b5e2617819ff4f7c78071dfd0275e971a9b6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9dbf091da080508e9f632d307f357beb79a0766b",
              "lessThan": "b64dd5f3b38911054cbcc570df617e3e8e75e562",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9dbf091da080508e9f632d307f357beb79a0766b",
              "lessThan": "31bbd4b87dd6701fa10e03ba7f6268e49e178d16",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9dbf091da080508e9f632d307f357beb79a0766b",
              "lessThan": "63203bd072b613c18c237b906b1c9d2dc4527337",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9dbf091da080508e9f632d307f357beb79a0766b",
              "lessThan": "15a0b3f33ffb6c78b3de6f69b026ceb09b973dd1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9dbf091da080508e9f632d307f357beb79a0766b",
              "lessThan": "cfc3283859cfdeacadf80d5e6880bdf871ffeaa6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9dbf091da080508e9f632d307f357beb79a0766b",
              "lessThan": "6bdc3023d62ed5c7d591f0eb27a5adb37fb892ae",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/iio/gyro/itg3200_buffer.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.9"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.9",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.259",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.210",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.176",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.143",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.93",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.35",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.0.12",
              "versionType": "semver",
              "lessThanOrEqual": "7.0.*"
            },
            {
              "status": "unaffected",
              "version": "7.1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/iio/gyro/itg3200_buffer.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-07-19T16:17:11.857",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/15a0b3f33ffb6c78b3de6f69b026ceb09b973dd1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/31bbd4b87dd6701fa10e03ba7f6268e49e178d16",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/63203bd072b613c18c237b906b1c9d2dc4527337",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6bdc3023d62ed5c7d591f0eb27a5adb37fb892ae",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8654b5e2617819ff4f7c78071dfd0275e971a9b6",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/90e809376b0f0d1ddec2eec954aecdd2a5b40b0e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b64dd5f3b38911054cbcc570df617e3e8e75e562",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cfc3283859cfdeacadf80d5e6880bdf871ffeaa6",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: gyro: itg3200: fix i2c read into the wrong stack location\n\nitg3200_read_all_channels() takes `__be16 *buf' as a parameter and\nfills the i2c_msg destination as `(char *)&buf'. Since `buf' is the\nparameter (a pointer), `&buf' is the address of the local pointer\nslot on the stack of itg3200_read_all_channels(), not the address\nof the caller's scan buffer. The (char *) cast hides the type\nmismatch.\n\ni2c_transfer() therefore writes ITG3200_SCAN_ELEMENTS * sizeof(s16)\n= 8 bytes into the parameter's stack slot, which is discarded when\nthe function returns. The caller's scan buffer in\nitg3200_trigger_handler() is never written to, so\niio_push_to_buffers_with_timestamp() pushes uninitialised stack\ncontents to userspace via /dev/iio:deviceX every scan -- both a\nfunctional bug (no actual gyroscope or temperature data is\ndelivered through the triggered buffer) and an information leak.\n\nThe non-buffered read_raw() path is unaffected: it goes through\nitg3200_read_reg_s16() which uses `&out' on a local s16 value,\nwhere that is correct.\n\nDrop the spurious `&' so the i2c read writes into the caller's\nbuffer."
    }
  ],
  "lastModified": "2026-07-27T17:44:23.777",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}