ieee802154: ca8210: fix pointer truncation in kfifo on 64-bit

Summary

CVECVE-2026-72047
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-08-15 06:21:13 UTC
Updated2026-08-15 06:21:13 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: ieee802154: ca8210: fix pointer truncation in kfifo on 64-bit ca8210_test_int_driver_write() and ca8210_test_int_user_read() exchange a kmalloc'd buffer pointer through a struct kfifo, but pass a literal '4' as the byte count to kfifo_in()/kfifo_out(). This is correct on 32-bit (pointer = 4 bytes), but on 64-bit only the low 4 bytes of the 8-byte pointer are written into the FIFO. The reader then reads back 4 bytes into an 8-byte local pointer variable, leaving the upper 4 bytes uninitialized stack data. The first dereference of the reconstructed pointer (fifo_buffer[1]) accesses an arbitrary kernel address and generally results in an oops. Use sizeof(fifo_buffer) so the byte count matches pointer width on every architecture. The driver has no architecture restriction in Kconfig, so any 64-bit build with CONFIG_IEEE802154_CA8210_DEBUGFS=y is exposed. Issue has been latent since the driver was added in 2017 because it is most commonly deployed on 32-bit MCUs. Found via a custom Coccinelle semantic patch hunting for short-byte kfifo I/O on byte-mode kfifos used to shuttle pointers.

Risk And Classification

EPSS: 0.002100000 probability, percentile 0.115350000 (date 2026-08-15)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected ded845a781a578dfb0b5b2c138e5a067aa3b1242 2c1664ccfae653979b38788211240b5a1ee317ed git Not specified
CNA Linux Linux affected ded845a781a578dfb0b5b2c138e5a067aa3b1242 093aacb0c56d5c693e3169a0224062e77c3fd0c0 git Not specified
CNA Linux Linux affected ded845a781a578dfb0b5b2c138e5a067aa3b1242 87dab14a4f68895d6f4d798e6ee3556cd64e8c72 git Not specified
CNA Linux Linux affected ded845a781a578dfb0b5b2c138e5a067aa3b1242 1fe2643d0b24ca3cdd61a31a45c2d3233dc6cbfe git Not specified
CNA Linux Linux affected ded845a781a578dfb0b5b2c138e5a067aa3b1242 65dc342274a01616f5c17105f7360a3b4bfd7a3d git Not specified
CNA Linux Linux affected ded845a781a578dfb0b5b2c138e5a067aa3b1242 2059c28bd725beded01277cdf1f67be33e714323 git Not specified
CNA Linux Linux affected ded845a781a578dfb0b5b2c138e5a067aa3b1242 d8ce67fa6a5e6929f5414e933ff9665176c2bce6 git Not specified
CNA Linux Linux affected ded845a781a578dfb0b5b2c138e5a067aa3b1242 6d7f7bcf225b2d566176bf6229dbd1252940cb3c git Not specified
CNA Linux Linux affected 4.12 Not specified
CNA Linux Linux unaffected 4.12 semver Not specified
CNA Linux Linux unaffected 5.10.261 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.212 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.178 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.145 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.97 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.40 6.18.* semver Not specified
CNA Linux Linux unaffected 7.1.5 7.1.* semver Not specified
CNA Linux Linux unaffected 7.2-rc1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/093aacb0c56d5c693e3169a0224062e77c3fd0c0 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/2c1664ccfae653979b38788211240b5a1ee317ed 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/6d7f7bcf225b2d566176bf6229dbd1252940cb3c 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/d8ce67fa6a5e6929f5414e933ff9665176c2bce6 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/1fe2643d0b24ca3cdd61a31a45c2d3233dc6cbfe 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/65dc342274a01616f5c17105f7360a3b4bfd7a3d 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/87dab14a4f68895d6f4d798e6ee3556cd64e8c72 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/2059c28bd725beded01277cdf1f67be33e714323 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report