Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-63934— iio: gyro: itg3200: fix i2c read into the wrong stack location

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会开源的一款操作系统内核。 Linux kernel 3.9版本存在安全漏洞,该漏洞源于itg3200驱动中i2c读取到错误的栈位置,导致未初始化的栈内容推送到用户空间,造成功能故障和信息泄露。

AI Predicted 7.8 Difficulty: Moderate EPSS 0.22% · P12

Possible ATT&CK Techniques 1 AI

T1005 · Data from Local System

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux 9dbf091da080508e9f632d307f357beb79a0766b< 90e809376b0f0d1ddec2eec954aecdd2a5b40b0e affected
9dbf091da080508e9f632d307f357beb79a0766b< 8654b5e2617819ff4f7c78071dfd0275e971a9b6 affected
9dbf091da080508e9f632d307f357beb79a0766b< b64dd5f3b38911054cbcc570df617e3e8e75e562 affected
9dbf091da080508e9f632d307f357beb79a0766b< 31bbd4b87dd6701fa10e03ba7f6268e49e178d16 affected
9dbf091da080508e9f632d307f357beb79a0766b< 63203bd072b613c18c237b906b1c9d2dc4527337 affected
9dbf091da080508e9f632d307f357beb79a0766b< 15a0b3f33ffb6c78b3de6f69b026ceb09b973dd1 affected
9dbf091da080508e9f632d307f357beb79a0766b< cfc3283859cfdeacadf80d5e6880bdf871ffeaa6 affected
9dbf091da080508e9f632d307f357beb79a0766b< 6bdc3023d62ed5c7d591f0eb27a5adb37fb892ae affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-63934

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
iio: gyro: itg3200: fix i2c read into the wrong stack location
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: iio: gyro: itg3200: fix i2c read into the wrong stack location itg3200_read_all_channels() takes `__be16 *buf' as a parameter and fills the i2c_msg destination as `(char *)&buf'. Since `buf' is the parameter (a pointer), `&buf' is the address of the local pointer slot on the stack of itg3200_read_all_channels(), not the address of the caller's scan buffer. The (char *) cast hides the type mismatch. i2c_transfer() therefore writes ITG3200_SCAN_ELEMENTS * sizeof(s16) = 8 bytes into the parameter's stack slot, which is discarded when the function returns. The caller's scan buffer in itg3200_trigger_handler() is never written to, so iio_push_to_buffers_with_timestamp() pushes uninitialised stack contents to userspace via /dev/iio:deviceX every scan -- both a functional bug (no actual gyroscope or temperature data is delivered through the triggered buffer) and an information leak. The non-buffered read_raw() path is unaffected: it goes through itg3200_read_reg_s16() which uses `&out' on a local s16 value, where that is correct. Drop the spurious `&' so the i2c read writes into the caller's buffer.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会开源的一款操作系统内核。 Linux kernel 3.9版本存在安全漏洞,该漏洞源于itg3200驱动中i2c读取到错误的栈位置,导致未初始化的栈内容推送到用户空间,造成功能故障和信息泄露。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 9dbf091da080508e9f632d307f357beb79a0766b ~ 90e809376b0f0d1ddec2eec954aecdd2a5b40b0e -
Linux Linux 3.9 -

II. Public POCs for CVE-2026-63934

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-63934

登录查看更多情报信息。

Patches & Fixes for CVE-2026-63934 (8)

Same Patch Batch · Linux · 2026-07-19 · 429 CVEs total

CVE-2026-63795 10.0 CRITICAL 9p: avoid putting oldfid in p9_client_walk() error path
CVE-2026-64037 9.8 CRITICAL wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled
CVE-2026-63993 9.8 CRITICAL vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu()
CVE-2026-63994 9.8 CRITICAL tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]()
CVE-2026-64142 9.8 CRITICAL ksmbd: close durable scavenger races against m_fp_list lookups
CVE-2026-64000 9.8 CRITICAL net: hsr: fix potential OOB access in supervision frame handling
CVE-2026-64046 9.8 CRITICAL net: tls: prevent chain-after-chain in plain text SG
CVE-2026-64162 9.8 CRITICAL idpf: fix read_dev_clk_lock spinlock init in idpf_ptp_init()
CVE-2026-53399 9.8 CRITICAL nfsd: release layout stid on setlease failure
CVE-2026-53398 9.8 CRITICAL NFSD: Fix SECINFO_NO_NAME decode error cleanup
CVE-2026-64007 9.8 CRITICAL netfilter: synproxy: refresh tcphdr after skb_ensure_writable
CVE-2026-63825 9.8 CRITICAL gcov: use atomic counter updates to fix concurrent access crashes
CVE-2026-64016 9.8 CRITICAL ksmbd: fix durable reconnect error path file lifetime
CVE-2026-63800 9.8 CRITICAL pNFS: Fix use-after-free in pnfs_update_layout()
CVE-2026-63808 9.8 CRITICAL exfat: fix potential use-after-free in exfat_find_dir_entry()
CVE-2026-64025 9.8 CRITICAL bpf, skmsg: fix verdict sk_data_ready racing with ktls rx
CVE-2026-64125 9.8 CRITICAL net: bcmgenet: keep RBUF EEE/PM disabled
CVE-2026-64033 9.8 CRITICAL RDMA/rtrs: Fix use-after-free in path file creation cleanup
CVE-2026-64089 9.8 CRITICAL batman-adv: tt: fix negative last_changeset_len
CVE-2026-64035 9.8 CRITICAL igc: set tx buffer type for SMD frames

Showing top 20 of 429 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-63934

No comments yet


Leave a comment