Buffer Overflow Vulnerability in BMG160 Gyroscope from Linux Kernel
CVE-2026-64495

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
25 July 2026

What is CVE-2026-64495?

The Linux kernel contains a buffer overflow vulnerability in the BMG160 gyroscope driver, which occurs when the function bmg160_get_filter() attempts to access an entry in the bmg160_samp_freq_table without verifying the input values. If an invalid bandwidth value is provided, the function may attempt to read beyond the limits of the array, leading to unexpected behavior and potential system instability. This vulnerability can be exploited from userspace through the sysfs interface, making it a concerning issue for users of affected products. Appropriate error handling has been implemented to return an error code when an invalid entry is detected, thereby mitigating the risk.

Affected Version(s)

Linux 22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc < 1dc3a833be11e5d503038e3c701745fd0e03903c

Linux 22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc < 77e56ebb1786f4296afd5fa46975a989b285ae65

Linux 22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc < 029481cddb98697716f4bf3021d035eaf2ca0e1f

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.