๐Ÿ” CVE Alert

CVE-2026-64495

UNKNOWN 0.0

iio: gyro: bmg160: bail out when bandwidth/filter is not in table

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: iio: gyro: bmg160: bail out when bandwidth/filter is not in table bmg160_get_filter() walks bmg160_samp_freq_table[] looking for the entry matching the bw_bits value read from the chip: for (i = 0; i < ARRAY_SIZE(bmg160_samp_freq_table); ++i) { if (bmg160_samp_freq_table[i].bw_bits == bw_bits) break; } *val = bmg160_samp_freq_table[i].filter; If no entry matches, i ends up equal to the array size and the next line reads one slot past the end. bmg160_set_filter() has the same shape, driven by 'val' instead of bw_bits. smatch flags both: drivers/iio/gyro/bmg160_core.c:204 bmg160_get_filter() error: buffer overflow 'bmg160_samp_freq_table' 7 <= 7 drivers/iio/gyro/bmg160_core.c:222 bmg160_set_filter() error: buffer overflow 'bmg160_samp_freq_table' 7 <= 7 Return -EINVAL when no entry matches. The set_filter() path is reachable from userspace via the sysfs in_anglvel_filter_low_pass_3db_frequency interface, so userspace can trivially trigger the out-of-bounds read with a value that is not in bmg160_samp_freq_table[].filter.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 25, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc < 1dc3a833be11e5d503038e3c701745fd0e03903c 22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc < 77e56ebb1786f4296afd5fa46975a989b285ae65 22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc < 029481cddb98697716f4bf3021d035eaf2ca0e1f 22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc < 8d202515baea4e2e3be448d1590099af28f2346d 22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc < d85ee50f58dd83fe74f6d0bf8bd345c657b216e8 22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc < 7bbf02b63961fc1768c9c654392c11f2077d4c59 22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc < 6c8675468862161d1c59130266852b66867d3861 22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc < 8320c77e67382d5d55d77043a5f60a867d408a2b
Linux / Linux
3.18

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/1dc3a833be11e5d503038e3c701745fd0e03903c git.kernel.org: https://git.kernel.org/stable/c/77e56ebb1786f4296afd5fa46975a989b285ae65 git.kernel.org: https://git.kernel.org/stable/c/029481cddb98697716f4bf3021d035eaf2ca0e1f git.kernel.org: https://git.kernel.org/stable/c/8d202515baea4e2e3be448d1590099af28f2346d git.kernel.org: https://git.kernel.org/stable/c/d85ee50f58dd83fe74f6d0bf8bd345c657b216e8 git.kernel.org: https://git.kernel.org/stable/c/7bbf02b63961fc1768c9c654392c11f2077d4c59 git.kernel.org: https://git.kernel.org/stable/c/6c8675468862161d1c59130266852b66867d3861 git.kernel.org: https://git.kernel.org/stable/c/8320c77e67382d5d55d77043a5f60a867d408a2b