Stack-based buffer overflow in Linux kernel - CVE-2026-64504
Published: July 27, 2026
Vulnerability details
The vulnerability allows an attacker with physical access to execute arbitrary code or cause a denial of service.
The vulnerability exists due to a stack-based buffer overflow in __bmc150_accel_fifo_flush() when processing a device-reported FIFO frame count. An attacker with physical access can tamper with the I2C/SPI bus or use a malicious device that reports an oversized frame count to execute arbitrary code or cause a denial of service.
The issue can overwrite the stack canary, saved registers, and return address during FIFO data transfer.
Affected software
How to mitigate CVE-2026-64504
External References
- https://git.kernel.org/stable/c/2fe0531dd73eff1de0f2584cb77716d645e548d5
- https://git.kernel.org/stable/c/35a3cd8fd65e15029eb90f1e510045b1bb071175
- https://git.kernel.org/stable/c/3e766526827acd542bcd36c20c4d5f397e0f6521
- https://git.kernel.org/stable/c/89f4a4ca0ac3a933c750569a771c079a290b0721
- https://git.kernel.org/stable/c/b5a9f521e0a49a0266200fd535b32a9668ecb33b
- https://git.kernel.org/stable/c/bfffc98f3de92e0f76be7c7b72e63ac1776a6dbc
- https://git.kernel.org/stable/c/ce0e1cae26096fe959a0da5563a6d6d5a801d5fb
- https://git.kernel.org/stable/c/d0e6d924a5484e005cae5aff6a0aa07a22f3c9ff