Stack Leak Vulnerability in Linux Kernel Affecting ADIS16550 IMU Products
CVE-2026-63966

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
19 July 2026

What is CVE-2026-63966?

A vulnerability in the Linux kernel related to the ADIS16550 IMU implementation exposes uninitialized stack data to userspace. The issue arises in the adis16550_trigger_handler() where the scan data array is declared on the stack without proper initialization. Consequently, only the first 28 bytes of data are filled with valid information, while the remaining bytes leak potentially sensitive data due to lack of zero-initialization. This flaw can impact the integrity of data processed by applications leveraging this functionality, leading to security risks.

Affected Version(s)

Linux e4570f4bb231f01e32d44fd38841665f340d6914

Linux e4570f4bb231f01e32d44fd38841665f340d6914

Linux e4570f4bb231f01e32d44fd38841665f340d6914 < 474f8928d50b09f7dcf507049f08732640b88b49

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.