hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer
Summary
| CVE | CVE-2026-64086 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-19 16:17:49 UTC |
| Updated | 2026-07-20 15:17:07 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer adm1266_pmbus_block_xfer() sets up the read transaction with .buf = data->read_buf, .len = ADM1266_PMBUS_BLOCK_MAX + 2, but read_buf in struct adm1266_data is declared as u8 read_buf[ADM1266_PMBUS_BLOCK_MAX + 1]; For a max-length block response (length byte = 255 + up to 1 PEC byte), the i2c controller is told to write 257 bytes into a 256-byte buffer, putting one byte past the end of read_buf. The same response also makes the subsequent PEC compare if (crc != msgs[1].buf[msgs[1].buf[0] + 1]) read a byte beyond the array. Bump the read_buf declaration to ADM1266_PMBUS_BLOCK_MAX + 2 so the buffer can hold the length byte, up to 255 payload bytes, and the PEC byte the i2c_msg length already accounts for. |
Risk And Classification
Primary CVSS: v3.1 7.8 HIGH from 416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.001840000 probability, percentile 0.082510000 (date 2026-07-20)
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | Secondary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | DECLARED | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 407dc802a9c0809ca6a48de4b4c63305eb84ef56 397d3f523bfff2f4e3dacf9b1339bd76dc207f78 git | Not specified |
| CNA | Linux | Linux | affected 407dc802a9c0809ca6a48de4b4c63305eb84ef56 472744f69d25a2d5111ad62f1d62579dce2c13c8 git | Not specified |
| CNA | Linux | Linux | affected 407dc802a9c0809ca6a48de4b4c63305eb84ef56 528a9f88e88502d0c2f2052a279415074cd83715 git | Not specified |
| CNA | Linux | Linux | affected 407dc802a9c0809ca6a48de4b4c63305eb84ef56 d94ceb16e55b6d8019ab069e357c76ac42f0ffbc git | Not specified |
| CNA | Linux | Linux | affected 407dc802a9c0809ca6a48de4b4c63305eb84ef56 bd5be3fa5de6dbf61f1b3cec6b79c2c2f8065694 git | Not specified |
| CNA | Linux | Linux | affected 407dc802a9c0809ca6a48de4b4c63305eb84ef56 2279c342d94eca225bf9f301c8806a05a1c81619 git | Not specified |
| CNA | Linux | Linux | affected 407dc802a9c0809ca6a48de4b4c63305eb84ef56 a6c802145a8de0830bca803c6d415f7e9e683624 git | Not specified |
| CNA | Linux | Linux | affected 407dc802a9c0809ca6a48de4b4c63305eb84ef56 487566cb1ccdf3756fdd7bf8d875e612ff3169bb git | Not specified |
| CNA | Linux | Linux | affected 5.10 | Not specified |
| CNA | Linux | Linux | unaffected 5.10 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.258 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.209 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.175 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.142 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.92 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.34 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.0.11 7.0.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.1 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/397d3f523bfff2f4e3dacf9b1339bd76dc207f78 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/d94ceb16e55b6d8019ab069e357c76ac42f0ffbc | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/bd5be3fa5de6dbf61f1b3cec6b79c2c2f8065694 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/472744f69d25a2d5111ad62f1d62579dce2c13c8 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/2279c342d94eca225bf9f301c8806a05a1c81619 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/a6c802145a8de0830bca803c6d415f7e9e683624 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/528a9f88e88502d0c2f2052a279415074cd83715 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/487566cb1ccdf3756fdd7bf8d875e612ff3169bb | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.