Stack Leak Vulnerability in Linux Kernel Affecting ADIS16550 IMU Products
CVE-2026-63966
Currently unrated
What is CVE-2026-63966?
A vulnerability in the Linux kernel related to the ADIS16550 IMU implementation exposes uninitialized stack data to userspace. The issue arises in the adis16550_trigger_handler() where the scan data array is declared on the stack without proper initialization. Consequently, only the first 28 bytes of data are filled with valid information, while the remaining bytes leak potentially sensitive data due to lack of zero-initialization. This flaw can impact the integrity of data processed by applications leveraging this functionality, leading to security risks.
Affected Version(s)
Linux e4570f4bb231f01e32d44fd38841665f340d6914
Linux e4570f4bb231f01e32d44fd38841665f340d6914
Linux e4570f4bb231f01e32d44fd38841665f340d6914 < 474f8928d50b09f7dcf507049f08732640b88b49