U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2026-64504

Change History

New CVE Received from kernel.org 7/25/2026 6:17:36 AM

Action Type Old Value New Value
Added Description

                  
                
              
In the Linux kernel, the following vulnerability has been resolved:

iio: accel: bmc150: clamp the device-reported FIFO frame count

__bmc150_accel_fifo_flush() copies the number of samples the device
reports in its hardware FIFO into an on-stack buffer

	u16 buffer[BMC150_ACCEL_FIFO_LENGTH * 3];

which is sized for at most BMC150_ACCEL_FIFO_LENGTH (32) samples. The
frame count is read from the FIFO_STATUS register and only masked to its
7 valid bits:

	count = val & 0x7F;

so it can be 0..127. The only other limit applied to it is the optional
caller-supplied sample budget:

	if (samples && count > samples)
		count = samples;

which does not constrain count on the flush-all path (samples == 0), and
leaves it well above 32 whenever samples is larger. count samples are
then transferred into buffer[]:

	bmc150_accel_fifo_transfer(data, (u8 *)buffer, count);

bmc150_accel_fifo_transfer() reads count * 6 bytes through regmap, so a
malfunctioning, malicious or counterfeit accelerometer (or an attacker
tampering with the I2C/SPI bus) that reports up to 127 frames writes up
to 762 bytes into the 192-byte buffer: a stack out-of-bounds write of up
to 570 bytes that clobbers the stack canary, saved registers and the
return address.

Clamp count to BMC150_ACCEL_FIFO_LENGTH, the number of samples buffer[]
is sized for, before the transfer, mirroring the watermark clamp already
done in bmc150_accel_set_watermark(). A well-formed flush reports at most
BMC150_ACCEL_FIFO_LENGTH frames, so legitimate devices are unaffected.
Added Reference

                  
                
              
https://git.kernel.org/stable/c/2fe0531dd73eff1de0f2584cb77716d645e548d5
Added Reference

                  
                
              
https://git.kernel.org/stable/c/35a3cd8fd65e15029eb90f1e510045b1bb071175
Added Reference

                  
                
              
https://git.kernel.org/stable/c/3e766526827acd542bcd36c20c4d5f397e0f6521
Added Reference

                  
                
              
https://git.kernel.org/stable/c/89f4a4ca0ac3a933c750569a771c079a290b0721
Added Reference

                  
                
              
https://git.kernel.org/stable/c/b5a9f521e0a49a0266200fd535b32a9668ecb33b
Added Reference

                  
                
              
https://git.kernel.org/stable/c/bfffc98f3de92e0f76be7c7b72e63ac1776a6dbc
Added Reference

                  
                
              
https://git.kernel.org/stable/c/ce0e1cae26096fe959a0da5563a6d6d5a801d5fb
Added Reference

                  
                
              
https://git.kernel.org/stable/c/d0e6d924a5484e005cae5aff6a0aa07a22f3c9ff
Added Affected

                  
                
              
[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/iio/accel/bmc150-accel-core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3bbec9773389112330954a6a64422eaa78d546c1","lessThan":"b5a9f521e0a49a0266200fd535b32a9668ecb33b","versionType":"git","status":"affected"},{"version":"3bbec9773389112330954a6a64422eaa78d546c1","lessThan":"2fe0531dd73eff1de0f2584cb77716d645e548d5","versionType":"git","status":"affected"},{"version":"3bbec9773389112330954a6a64422eaa78d546c1","lessThan":"d0e6d924a5484e005cae5aff6a0aa07a22f3c9ff","versionType":"git","status":"affected"},{"version":"3bbec9773389112330954a6a64422eaa78d546c1","lessThan":"bfffc98f3de92e0f76be7c7b72e63ac1776a6dbc","versionType":"git","status":"affected"},{"version":"3bbec9773389112330954a6a64422eaa78d546c1","lessThan":"89f4a4ca0ac3a933c750569a771c079a290b0721","versionType":"git","status":"affected"},{"version":"3bbec9773389112330954a6a64422eaa78d546c1","lessThan":"3e766526827acd542bcd36c20c4d5f397e0f6521","versionType":"git","status":"affected"},{"version":"3bbec9773389112330954a6a64422eaa78d546c1","lessThan":"35a3cd8fd65e15029eb90f1e510045b1bb071175","versionType":"git","status":"affected"},{"version":"3bbec9773389112330954a6a64422eaa78d546c1","lessThan":"ce0e1cae26096fe959a0da5563a6d6d5a801d5fb","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/iio/accel/bmc150-accel-core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.1","status":"affected"},{"version":"0","lessThan":"4.1","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]