CVE-2026-63966
iio: imu: adis16550: fix stack leak in trigger handler
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
In the Linux kernel, the following vulnerability has been resolved: iio: imu: adis16550: fix stack leak in trigger handler adis16550_trigger_handler() declares the scan data array on the stack without initializing it. The memcpy() at the bottom fills only the first 28 bytes (TEMP + 6 channels of GYRO/ACCEL data), and iio_push_to_buffers_with_timestamp() writes the s64 timestamp at the 8-byte-aligned offset 32. Bytes 28-31 remain uninitialized stack data which leaks to userspace on ever trigger. Fix this all by just zero-initializing the structure on the stack.
| Vendor | linux |
| Product | linux |
| Ecosystems | |
| Industries | Technology |
| Published | Jul 19, 2026 |
Stay Ahead of the Next One
Get instant alerts for linux linux
Be the first to know when new unknown vulnerabilities affecting linux linux are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Linux / Linux
e4570f4bb231f01e32d44fd38841665f340d6914 < ce582b22dd2ff15ac99101c22ec1559d1febe2ff e4570f4bb231f01e32d44fd38841665f340d6914 < c2c255444392872cbbf46d640cb3a938e8000309 e4570f4bb231f01e32d44fd38841665f340d6914 < 474f8928d50b09f7dcf507049f08732640b88b49
Linux / Linux
6.15