{"api_version":"1","generated_at":"2026-07-23T15:42:18+00:00","cve":"CVE-2026-64086","urls":{"html":"https://cve.report/CVE-2026-64086","api":"https://cve.report/api/cve/CVE-2026-64086.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-64086","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-64086"},"summary":{"title":"hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer\n\nadm1266_pmbus_block_xfer() sets up the read transaction with\n\n\t.buf = data->read_buf,\n\t.len = ADM1266_PMBUS_BLOCK_MAX + 2,\n\nbut read_buf in struct adm1266_data is declared as\n\n\tu8 read_buf[ADM1266_PMBUS_BLOCK_MAX + 1];\n\nFor a max-length block response (length byte = 255 + up to 1 PEC\nbyte), the i2c controller is told to write 257 bytes into a 256-byte\nbuffer, putting one byte past the end of read_buf.  The same response\nalso makes the subsequent PEC compare\n\n\tif (crc != msgs[1].buf[msgs[1].buf[0] + 1])\n\nread a byte beyond the array.\n\nBump the read_buf declaration to ADM1266_PMBUS_BLOCK_MAX + 2 so the\nbuffer can hold the length byte, up to 255 payload bytes, and the PEC\nbyte the i2c_msg length already accounts for.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-07-19 16:17:49","updated_at":"2026-07-20 15:17:07"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/397d3f523bfff2f4e3dacf9b1339bd76dc207f78","name":"https://git.kernel.org/stable/c/397d3f523bfff2f4e3dacf9b1339bd76dc207f78","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/d94ceb16e55b6d8019ab069e357c76ac42f0ffbc","name":"https://git.kernel.org/stable/c/d94ceb16e55b6d8019ab069e357c76ac42f0ffbc","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/bd5be3fa5de6dbf61f1b3cec6b79c2c2f8065694","name":"https://git.kernel.org/stable/c/bd5be3fa5de6dbf61f1b3cec6b79c2c2f8065694","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/472744f69d25a2d5111ad62f1d62579dce2c13c8","name":"https://git.kernel.org/stable/c/472744f69d25a2d5111ad62f1d62579dce2c13c8","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/2279c342d94eca225bf9f301c8806a05a1c81619","name":"https://git.kernel.org/stable/c/2279c342d94eca225bf9f301c8806a05a1c81619","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/a6c802145a8de0830bca803c6d415f7e9e683624","name":"https://git.kernel.org/stable/c/a6c802145a8de0830bca803c6d415f7e9e683624","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/528a9f88e88502d0c2f2052a279415074cd83715","name":"https://git.kernel.org/stable/c/528a9f88e88502d0c2f2052a279415074cd83715","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/487566cb1ccdf3756fdd7bf8d875e612ff3169bb","name":"https://git.kernel.org/stable/c/487566cb1ccdf3756fdd7bf8d875e612ff3169bb","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-64086","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64086","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 407dc802a9c0809ca6a48de4b4c63305eb84ef56 397d3f523bfff2f4e3dacf9b1339bd76dc207f78 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 407dc802a9c0809ca6a48de4b4c63305eb84ef56 472744f69d25a2d5111ad62f1d62579dce2c13c8 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 407dc802a9c0809ca6a48de4b4c63305eb84ef56 528a9f88e88502d0c2f2052a279415074cd83715 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 407dc802a9c0809ca6a48de4b4c63305eb84ef56 d94ceb16e55b6d8019ab069e357c76ac42f0ffbc git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 407dc802a9c0809ca6a48de4b4c63305eb84ef56 bd5be3fa5de6dbf61f1b3cec6b79c2c2f8065694 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 407dc802a9c0809ca6a48de4b4c63305eb84ef56 2279c342d94eca225bf9f301c8806a05a1c81619 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 407dc802a9c0809ca6a48de4b4c63305eb84ef56 a6c802145a8de0830bca803c6d415f7e9e683624 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 407dc802a9c0809ca6a48de4b4c63305eb84ef56 487566cb1ccdf3756fdd7bf8d875e612ff3169bb git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.10","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.10 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.10.258 5.10.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.15.209 5.15.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.175 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.142 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.92 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.34 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.0.11 7.0.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"64086","cve":"CVE-2026-64086","epss":"0.001840000","percentile":"0.082510000","score_date":"2026-07-20","updated_at":"2026-07-21 00:13:13"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/hwmon/pmbus/adm1266.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"397d3f523bfff2f4e3dacf9b1339bd76dc207f78","status":"affected","version":"407dc802a9c0809ca6a48de4b4c63305eb84ef56","versionType":"git"},{"lessThan":"472744f69d25a2d5111ad62f1d62579dce2c13c8","status":"affected","version":"407dc802a9c0809ca6a48de4b4c63305eb84ef56","versionType":"git"},{"lessThan":"528a9f88e88502d0c2f2052a279415074cd83715","status":"affected","version":"407dc802a9c0809ca6a48de4b4c63305eb84ef56","versionType":"git"},{"lessThan":"d94ceb16e55b6d8019ab069e357c76ac42f0ffbc","status":"affected","version":"407dc802a9c0809ca6a48de4b4c63305eb84ef56","versionType":"git"},{"lessThan":"bd5be3fa5de6dbf61f1b3cec6b79c2c2f8065694","status":"affected","version":"407dc802a9c0809ca6a48de4b4c63305eb84ef56","versionType":"git"},{"lessThan":"2279c342d94eca225bf9f301c8806a05a1c81619","status":"affected","version":"407dc802a9c0809ca6a48de4b4c63305eb84ef56","versionType":"git"},{"lessThan":"a6c802145a8de0830bca803c6d415f7e9e683624","status":"affected","version":"407dc802a9c0809ca6a48de4b4c63305eb84ef56","versionType":"git"},{"lessThan":"487566cb1ccdf3756fdd7bf8d875e612ff3169bb","status":"affected","version":"407dc802a9c0809ca6a48de4b4c63305eb84ef56","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/hwmon/pmbus/adm1266.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"5.10"},{"lessThan":"5.10","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"5.10.*","status":"unaffected","version":"5.10.258","versionType":"semver"},{"lessThanOrEqual":"5.15.*","status":"unaffected","version":"5.15.209","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.175","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.142","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.92","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.34","versionType":"semver"},{"lessThanOrEqual":"7.0.*","status":"unaffected","version":"7.0.11","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.10.258","versionStartIncluding":"5.10","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.15.209","versionStartIncluding":"5.10","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.175","versionStartIncluding":"5.10","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.142","versionStartIncluding":"5.10","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.92","versionStartIncluding":"5.10","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.34","versionStartIncluding":"5.10","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.0.11","versionStartIncluding":"5.10","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1","versionStartIncluding":"5.10","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer\n\nadm1266_pmbus_block_xfer() sets up the read transaction with\n\n\t.buf = data->read_buf,\n\t.len = ADM1266_PMBUS_BLOCK_MAX + 2,\n\nbut read_buf in struct adm1266_data is declared as\n\n\tu8 read_buf[ADM1266_PMBUS_BLOCK_MAX + 1];\n\nFor a max-length block response (length byte = 255 + up to 1 PEC\nbyte), the i2c controller is told to write 257 bytes into a 256-byte\nbuffer, putting one byte past the end of read_buf.  The same response\nalso makes the subsequent PEC compare\n\n\tif (crc != msgs[1].buf[msgs[1].buf[0] + 1])\n\nread a byte beyond the array.\n\nBump the read_buf declaration to ADM1266_PMBUS_BLOCK_MAX + 2 so the\nbuffer can hold the length byte, up to 255 payload bytes, and the PEC\nbyte the i2c_msg length already accounts for."}],"metrics":[{"cvssV3_1":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"providerMetadata":{"dateUpdated":"2026-07-20T13:43:10.387Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/397d3f523bfff2f4e3dacf9b1339bd76dc207f78"},{"url":"https://git.kernel.org/stable/c/472744f69d25a2d5111ad62f1d62579dce2c13c8"},{"url":"https://git.kernel.org/stable/c/528a9f88e88502d0c2f2052a279415074cd83715"},{"url":"https://git.kernel.org/stable/c/d94ceb16e55b6d8019ab069e357c76ac42f0ffbc"},{"url":"https://git.kernel.org/stable/c/bd5be3fa5de6dbf61f1b3cec6b79c2c2f8065694"},{"url":"https://git.kernel.org/stable/c/2279c342d94eca225bf9f301c8806a05a1c81619"},{"url":"https://git.kernel.org/stable/c/a6c802145a8de0830bca803c6d415f7e9e683624"},{"url":"https://git.kernel.org/stable/c/487566cb1ccdf3756fdd7bf8d875e612ff3169bb"}],"title":"hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-64086","datePublished":"2026-07-19T15:39:56.749Z","dateReserved":"2026-07-19T07:54:57.032Z","dateUpdated":"2026-07-20T13:43:10.387Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-07-19 16:17:49","lastModifiedDate":"2026-07-20 15:17:07","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"64086","Ordinal":"1","Title":"hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read","CVE":"CVE-2026-64086","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"64086","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer\n\nadm1266_pmbus_block_xfer() sets up the read transaction with\n\n\t.buf = data->read_buf,\n\t.len = ADM1266_PMBUS_BLOCK_MAX + 2,\n\nbut read_buf in struct adm1266_data is declared as\n\n\tu8 read_buf[ADM1266_PMBUS_BLOCK_MAX + 1];\n\nFor a max-length block response (length byte = 255 + up to 1 PEC\nbyte), the i2c controller is told to write 257 bytes into a 256-byte\nbuffer, putting one byte past the end of read_buf.  The same response\nalso makes the subsequent PEC compare\n\n\tif (crc != msgs[1].buf[msgs[1].buf[0] + 1])\n\nread a byte beyond the array.\n\nBump the read_buf declaration to ADM1266_PMBUS_BLOCK_MAX + 2 so the\nbuffer can hold the length byte, up to 255 payload bytes, and the PEC\nbyte the i2c_msg length already accounts for.","Type":"Description","Title":"hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read"}]}}}