Out-of-bounds Write Vulnerability in BMC150 Accelerometer Driver for Linux Kernel
CVE-2026-64504
What is CVE-2026-64504?
This vulnerability impacts the BMC150 accelerometer driver in the Linux kernel, where a misreported FIFO frame count can lead to an out-of-bounds write in the stack. The driver inadequately validates the number of frames reported by the hardware, potentially allowing a malicious device or an attacker to send an inflated count. This defect can result in transferring excess data into a buffer, exceeding its allocated size, and leading to stack corruption. Legitimate devices are safeguarded by the clamping mechanism implemented, ensuring they report a suitable number of frames.
Affected Version(s)
Linux 3bbec9773389112330954a6a64422eaa78d546c1
Linux 3bbec9773389112330954a6a64422eaa78d546c1 < 2fe0531dd73eff1de0f2584cb77716d645e548d5
Linux 3bbec9773389112330954a6a64422eaa78d546c1