{"cvss":5.5,"datePublished":"2026-07-19T16:17:49.433","dateUpdated":"2026-09-03T16:12:43.563","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (pmbus/adm1266) reject implausible blackbox record_count\n\nadm1266_nvmem_read_blackbox() loops over a record_count that comes\nstraight from byte 3 of the BLACKBOX_INFO response.  The destination\nbuffer is data->dev_mem, sized for the nvmem cell's declared 2048\nbytes (ADM1266_BLACKBOX_MAX_RECORDS * ADM1266_BLACKBOX_SIZE = 32 * 64).\nA device that reports a record_count greater than 32 -- whether due\nto firmware bugs, bus corruption, or a non-responsive slave returning\n0xff -- would walk read_buff past the end of the dev_mem allocation\non the trailing iterations.\n\nCap record_count at ADM1266_BLACKBOX_MAX_RECORDS (introduced here)\nbefore entering the loop and return -EIO on any larger value, so a\nmalformed BLACKBOX_INFO response cannot drive the loop out of bounds.","id":"CVE-2026-64087","raw":{"affected":[{"affectedData":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/hwmon/pmbus/adm1266.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"adcb163ad7cacca317872fc62bd8885e842e45e3","status":"affected","version":"15609d1893020436e1e8ccfd9ded774a96dd17a2","versionType":"git"},{"lessThan":"c2c56092710fe8a893b67b5a3d7e62808d02d84d","status":"affected","version":"15609d1893020436e1e8ccfd9ded774a96dd17a2","versionType":"git"},{"lessThan":"5469e1e7c411acc15fdd8262c99c3ebd9defd594","status":"affected","version":"15609d1893020436e1e8ccfd9ded774a96dd17a2","versionType":"git"},{"lessThan":"f85c81e93dbd6915970bd5f3bffcf62633c4c54c","status":"affected","version":"15609d1893020436e1e8ccfd9ded774a96dd17a2","versionType":"git"},{"lessThan":"0e791cd0140fb136083565aadfbe0f705aa260d0","status":"affected","version":"15609d1893020436e1e8ccfd9ded774a96dd17a2","versionType":"git"},{"lessThan":"75c862adf3d3caab4f49bb3530723c215376e37c","status":"affected","version":"15609d1893020436e1e8ccfd9ded774a96dd17a2","versionType":"git"},{"lessThan":"231db52a5b64d0a9769e298dadc148e1f79b26a6","status":"affected","version":"15609d1893020436e1e8ccfd9ded774a96dd17a2","versionType":"git"},{"lessThan":"4afca954622d672ea65ed961bed01cf91caa034e","status":"affected","version":"15609d1893020436e1e8ccfd9ded774a96dd17a2","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/hwmon/pmbus/adm1266.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"5.10"},{"lessThan":"5.10","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"5.10.*","status":"unaffected","version":"5.10.258","versionType":"semver"},{"lessThanOrEqual":"5.15.*","status":"unaffected","version":"5.15.209","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.175","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.142","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.92","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.34","versionType":"semver"},{"lessThanOrEqual":"7.0.*","status":"unaffected","version":"7.0.11","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.1","versionType":"original_commit_for_fix"}]}],"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"configurations":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","matchCriteriaId":"2DF65560-A687-49D3-8FB4-E612C0BD541C","versionEndExcluding":"5.10.258","versionStartIncluding":"5.10","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","matchCriteriaId":"919C10A9-7951-4A74-BADD-C135A0A8D8B4","versionEndExcluding":"5.15.209","versionStartIncluding":"5.11","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","matchCriteriaId":"92385813-D91D-480D-83A1-F423D2CBB2BA","versionEndExcluding":"6.1.175","versionStartIncluding":"5.16","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","matchCriteriaId":"FBFF77B0-526A-4AF1-84D0-ED7187624A67","versionEndExcluding":"6.6.142","versionStartIncluding":"6.2","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","matchCriteriaId":"9CB90BD9-95B7-4D7F-9F17-4ECE6CFB66C9","versionEndExcluding":"6.12.92","versionStartIncluding":"6.7","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","matchCriteriaId":"A4B1EF6D-18D7-4838-BC37-7499D5DCC3C0","versionEndExcluding":"6.18.34","versionStartIncluding":"6.13","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","matchCriteriaId":"0520D091-FC52-4A50-AF07-70AE7D08B750","versionEndExcluding":"7.0.11","versionStartIncluding":"6.19","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*","matchCriteriaId":"B1EF7059-E670-45F4-B422-54C40FA86390","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*","matchCriteriaId":"0D38F0BF-A728-4133-A358-D44A2F7EE6D6","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*","matchCriteriaId":"EC732D08-5F7B-46D9-B154-E60C7F4F0A97","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*","matchCriteriaId":"E5910A9D-F60A-409A-B486-FE66BFEBA9B9","vulnerable":true}],"negate":false,"operator":"OR"}]}],"cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (pmbus/adm1266) reject implausible blackbox record_count\n\nadm1266_nvmem_read_blackbox() loops over a record_count that comes\nstraight from byte 3 of the BLACKBOX_INFO response.  The destination\nbuffer is data->dev_mem, sized for the nvmem cell's declared 2048\nbytes (ADM1266_BLACKBOX_MAX_RECORDS * ADM1266_BLACKBOX_SIZE = 32 * 64).\nA device that reports a record_count greater than 32 -- whether due\nto firmware bugs, bus corruption, or a non-responsive slave returning\n0xff -- would walk read_buff past the end of the dev_mem allocation\non the trailing iterations.\n\nCap record_count at ADM1266_BLACKBOX_MAX_RECORDS (introduced here)\nbefore entering the loop and return -EIO on any larger value, so a\nmalformed BLACKBOX_INFO response cannot drive the loop out of bounds."}],"id":"CVE-2026-64087","lastModified":"2026-09-03T16:12:43.563","metrics":{"cvssMetricV31":[{"cvssData":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"exploitabilityScore":1.8,"impactScore":3.6,"source":"nvd@nist.gov","type":"Primary"}]},"published":"2026-07-19T16:17:49.433","references":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"url":"https://git.kernel.org/stable/c/0e791cd0140fb136083565aadfbe0f705aa260d0"},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"url":"https://git.kernel.org/stable/c/231db52a5b64d0a9769e298dadc148e1f79b26a6"},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"url":"https://git.kernel.org/stable/c/4afca954622d672ea65ed961bed01cf91caa034e"},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"url":"https://git.kernel.org/stable/c/5469e1e7c411acc15fdd8262c99c3ebd9defd594"},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"url":"https://git.kernel.org/stable/c/75c862adf3d3caab4f49bb3530723c215376e37c"},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"url":"https://git.kernel.org/stable/c/adcb163ad7cacca317872fc62bd8885e842e45e3"},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"url":"https://git.kernel.org/stable/c/c2c56092710fe8a893b67b5a3d7e62808d02d84d"},{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"url":"https://git.kernel.org/stable/c/f85c81e93dbd6915970bd5f3bffcf62633c4c54c"}],"sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","vulnStatus":"Analyzed","weaknesses":[{"description":[{"lang":"en","value":"NVD-CWE-noinfo"}],"source":"nvd@nist.gov","type":"Primary"}]},"severity":"MEDIUM","source":"nvd","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (pmbus/adm1266) reject implausible blackb..."}