CVE-2026-64087

UnknownEPSS 0.18%

Last modified

CVE-2026-64087 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus/adm1266) reject implausible blackbox record_count adm1266_nvmem_read_blackbox() loops over a record_count that comes straight from byte 3 of the BLACKBOX_INFO response. The destination buffer is data->dev_mem, sized for the nvmem cell's declared 2048 bytes (ADM1266_BLACKBOX_MAX_RECORDS * ADM1266_BLACKBOX_SIZE = 32 * 64). A device that reports a record_count greater than 32 -- whether due to firmware bugs, bus corruption, or a non-responsive slave returning 0xff -- would walk read_buff past the end of the dev_mem allocation on the trailing iterations. Cap record_count at ADM1266_BLACKBOX_MAX_RECORDS (introduced here) before entering the loop and return -EIO on any larger value, so a malformed BLACKBOX_INFO response cannot drive the loop out of bounds.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus/adm1266) reject implausible blackbox record_count adm1266_nvmem_read_blackbox() loops over a record_count that comes straight from byte 3 of the BLACKBOX_INFO response. The destination buffer is data->dev_mem, sized for the nvmem cell's declared 2048 bytes (ADM1266_BLACKBOX_MAX_RECORDS * ADM1266_BLACKBOX_SIZE = 32 * 64). A device that reports a record_count greater than 32 -- whether due to firmware bugs, bus corruption, or a non-responsive slave returning 0xff -- would walk read_buff past the end of the dev_mem allocation on the trailing iterations. Cap record_count at ADM1266_BLACKBOX_MAX_RECORDS (introduced here) before entering the loop and return -EIO on any larger value, so a malformed BLACKBOX_INFO response cannot drive the loop out of bounds.

Metrics

EPSS Probability
0.18%

8.3th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 15609d1893020436e1e8ccfd9ded774a96dd17a2, < adcb163ad7cacca317872fc62bd8885e842e45e3; >= 15609d1893020436e1e8ccfd9ded774a96dd17a2, < c2c56092710fe8a893b67b5a3d7e62808d02d84d; >= 15609d1893020436e1e8ccfd9ded774a96dd17a2, < 5469e1e7c411acc15fdd8262c99c3ebd9defd594; >= 15609d1893020436e1e8ccfd9ded774a96dd17a2, < f85c81e93dbd6915970bd5f3bffcf62633c4c54c; >= 15609d1893020436e1e8ccfd9ded774a96dd17a2, < 0e791cd0140fb136083565aadfbe0f705aa260d0; >= 15609d1893020436e1e8ccfd9ded774a96dd17a2, < 75c862adf3d3caab4f49bb3530723c215376e37c; >= 15609d1893020436e1e8ccfd9ded774a96dd17a2, < 231db52a5b64d0a9769e298dadc148e1f79b26a6; >= 15609d1893020436e1e8ccfd9ded774a96dd17a2, < 4afca954622d672ea65ed961bed01cf91caa034e
LinuxLinux5.10

References

Timeline

Published
Last Modified
Status
Awaiting Analysis

Frequently Asked Questions

What is CVE-2026-64087?
In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus/adm1266) reject implausible blackbox record_count adm1266_nvmem_read_blackbox() loops over a record_count that comes straight from byte 3 of the BLACKBOX_INFO response. The destination buffer is data->dev_mem, sized for the nvmem cell's declared 2048 bytes (ADM1266_BLACKBOX_MAX_RECORDS * ADM1266_BLACKBOX_SIZE = 32 * 64). A device that reports a record_count greater than 32 -- whether due to firmware bugs, bus corruption, or a non-responsive slave returning 0xff -- would walk read_buff past the end of the dev_mem allocation on the trailing iterations. Cap record_count at ADM1266_BLACKBOX_MAX_RECORDS (introduced here) before entering the loop and return -EIO on any larger value, so a malformed BLACKBOX_INFO response cannot drive the loop out of bounds.
How severe is CVE-2026-64087?
Severity scoring for CVE-2026-64087 is pending analysis. The EPSS model estimates a 0.18% probability of exploitation in the next 30 days.
How do I fix CVE-2026-64087?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-64087?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST