CVE-2026-63967

UnknownEPSS 0.21%

Last modified

CVE-2026-63967 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer The tagged FIFO path declares iio_buff on the stack with __aligned(8) but no initializer, but there is a hole in the structure, which will then leak to userspace as ST_LSM6DSX_SAMPLE_SIZE bytes (6) will be copied, but the space between that and the timestamp are not initialized. Commit c14edb4d0bdc ("iio:imu:st_lsm6dsx Fix alignment and data leak issues") moved the untagged FIFO path to a kzalloc'd buffer in hw->scan, but for the tagged path it only added the alignment qualifier and not the initializer :( Fix this by just zero-initializing the structure on the stack.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer The tagged FIFO path declares iio_buff on the stack with __aligned(8) but no initializer, but there is a hole in the structure, which will then leak to userspace as ST_LSM6DSX_SAMPLE_SIZE bytes (6) will be copied, but the space between that and the timestamp are not initialized. Commit c14edb4d0bdc ("iio:imu:st_lsm6dsx Fix alignment and data leak issues") moved the untagged FIFO path to a kzalloc'd buffer in hw->scan, but for the tagged path it only added the alignment qualifier and not the initializer :( Fix this by just zero-initializing the structure on the stack.

Metrics

EPSS Probability
0.21%

11.5th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= c14edb4d0bdc53f969ea84c7f384472c28b1a9f8, < ff8d3c088b77b11782f2c3b97e37425be050e8de; >= c14edb4d0bdc53f969ea84c7f384472c28b1a9f8, < fe1a7f99e72ebd2880515332b79b8c256be22aca; >= c14edb4d0bdc53f969ea84c7f384472c28b1a9f8, < babf1943a40bb5669db57d30ca16c22504b18e07; >= c14edb4d0bdc53f969ea84c7f384472c28b1a9f8, < d42ac0bfb6a16617c62a59d53706579c7fadbfa6; >= c14edb4d0bdc53f969ea84c7f384472c28b1a9f8, < 3147b303b8c7d9f91da4b849ece33b45048f5eaf; >= c14edb4d0bdc53f969ea84c7f384472c28b1a9f8, < e6bb3a49c5f9de870ea95e69775df785728e3366; >= c14edb4d0bdc53f969ea84c7f384472c28b1a9f8, < 890d0312d5f94be43eac21f5a34d3bccc60d051b; >= c14edb4d0bdc53f969ea84c7f384472c28b1a9f8, < c9d8e9adaa63150ef7e833480b799d0bab83a276; a42ca3b182ccb766666a0be1053921cba190e2de; >= 5.9.5, < 5.10
LinuxLinux5.10

References

Timeline

Published
Last Modified
Status
Awaiting Analysis

Frequently Asked Questions

What is CVE-2026-63967?
In the Linux kernel, the following vulnerability has been resolved: iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer The tagged FIFO path declares iio_buff on the stack with __aligned(8) but no initializer, but there is a hole in the structure, which will then leak to userspace as ST_LSM6DSX_SAMPLE_SIZE bytes (6) will be copied, but the space between that and the timestamp are not initialized. Commit c14edb4d0bdc ("iio:imu:st_lsm6dsx Fix alignment and data leak issues") moved the untagged FIFO path to a kzalloc'd buffer in hw->scan, but for the tagged path it only added the alignment qualifier and not the initializer :( Fix this by just zero-initializing the structure on the stack.
How severe is CVE-2026-63967?
Severity scoring for CVE-2026-63967 is pending analysis. The EPSS model estimates a 0.21% probability of exploitation in the next 30 days.
How do I fix CVE-2026-63967?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-63967?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST