SB20260720156 - Use of Uninitialized Variable in Linux kernel hwmon pmbus driver
Published: July 20, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use of Uninitialized Variable (CVE-ID: CVE-2026-64083)
CWE-ID: CWE-457 - Use of Uninitialized Variable
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an uninitialized stack memory exposure in the adm1266 GPIO accessors when processing short block-read responses from the device. A local user can trigger a short block-read response to disclose sensitive information.
The leaked bits can reach userspace through gpiolib interfaces including sysfs and character-device ioctls.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/64fa9328948ddcc0f7f3c23ea1756c126d9dffac
- https://git.kernel.org/stable/c/a2d1c819348b36fccbbfcf37c5fa7a50a9b4528f
- https://git.kernel.org/stable/c/a7232f68c43ca62f545049b7f5fbfc75137b843b
- https://git.kernel.org/stable/c/ae25cf2ea9ebd06d7ad416647dbdc7b5d0172946
- https://git.kernel.org/stable/c/c603b6c6840ac0c6285f5eefea0de6242710af21
- https://git.kernel.org/stable/c/eb3cd9bb590460c6127145cb245be925d23f5232
- https://git.kernel.org/stable/c/ee4799becf7d2af3778007e22c2e55c4009a49c7
- https://git.kernel.org/stable/c/fd9196aad9e5a3845cea17de3405ebc700382142