CVE-2026-63965
Last modified
CVE-2026-63965 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: iio: pressure: bmp280: fix stack leak in bmp580 trigger handler bmp580_trigger_handler() declares its scan buffer on the stack without an initializer and then memcpy()s 3 bytes of 24-bit sensor data into each 4-byte __le32 field. The high byte of comp_temp and comp_press is left uninitialized, and the channel storagebits is 32, so two bytes of stack are pushed to userspace per scan. This is a regression from when the buffer lived in the private data, the move to a stack-local struct dropped the implicit zeroing. bme280_trigger_handler() was fixed up to handle this bug, but this driver was not fixed because there was no padding hole, but rather a short-fill issue. Fix this all by just zero-initializing the structure on the stack.. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: iio: pressure: bmp280: fix stack leak in bmp580 trigger handler bmp580_trigger_handler() declares its scan buffer on the stack without an initializer and then memcpy()s 3 bytes of 24-bit sensor data into each 4-byte __le32 field. The high byte of comp_temp and comp_press is left uninitialized, and the channel storagebits is 32, so two bytes of stack are pushed to userspace per scan. This is a regression from when the buffer lived in the private data, the move to a stack-local struct dropped the implicit zeroing. bme280_trigger_handler() was fixed up to handle this bug, but this driver was not fixed because there was no padding hole, but rather a short-fill issue. Fix this all by just zero-initializing the structure on the stack.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 872c8014e05ed47b8a7c0f5ba4311279a637150b, < a58400f58f82f3d8de9c067aa7cda690228c1ecc; >= 872c8014e05ed47b8a7c0f5ba4311279a637150b, < 58dfb6fe9dc80270cf7cc014837af4cbf928e3aa; >= 872c8014e05ed47b8a7c0f5ba4311279a637150b, < 387c86b582e0782ab332e7bfcd4e6e3f93922961 |
| Linux | Linux | 6.16 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-63965?
How severe is CVE-2026-63965?
How do I fix CVE-2026-63965?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-6396The Fast & Fancy Filter – 3F plugin for WordPress is vulnera…4.3
- CVE-2026-63960In the Linux kernel, the following vulnerability has been re…
- CVE-2026-63961In the Linux kernel, the following vulnerability has been re…
- CVE-2026-63962In the Linux kernel, the following vulnerability has been re…
- CVE-2026-63963In the Linux kernel, the following vulnerability has been re…
- CVE-2026-63964In the Linux kernel, the following vulnerability has been re…
- CVE-2026-63966In the Linux kernel, the following vulnerability has been re…
- CVE-2026-63967In the Linux kernel, the following vulnerability has been re…
- CVE-2026-63968In the Linux kernel, the following vulnerability has been re…7.5
- CVE-2026-63969In the Linux kernel, the following vulnerability has been re…
- CVE-2026-6397The Sticky plugin for WordPress is vulnerable to Stored Cros…6.4
- CVE-2026-63970In the Linux kernel, the following vulnerability has been re…7.8
Are you affected by CVE-2026-63965?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
