CVE-2026-63936

Summary

In the Linux kernel, the following vulnerability has been resolved:

iio: adc: mt6359: fix unchecked return value in mt6358_read_imp

In mt6358_read_imp(), the variable val_v is passed to regmap_read() but the return value is not checked. If the read fails, val_v remains uninitialized and its random stack content is subsequently reported as a measurement result.

Initialize val_v to zero to ensure a predictable value is reported in case of bus failure and to prevent potential stack data leakage. This also satisfies static analyzers that might otherwise flag the variable as used uninitialized.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux3587914bf61df7924933530353d840378cdc4973 < 6258bfec51e894ea97b8e69f3cde7af269b37de9affected
LinuxLinux3587914bf61df7924933530353d840378cdc4973 < 944082fdb0284a31c0b37a88c8a1d4404da3a6d9affected
LinuxLinux3587914bf61df7924933530353d840378cdc4973 < a72f8e51d6ee66c255a8a93a4421b8a538d112a8affected
LinuxLinux3587914bf61df7924933530353d840378cdc4973 < f9bbd943c34a9ad60e593a4b99ce2394e4e2381baffected
LinuxLinux6.11affected
LinuxLinux0 < 6.11unaffected
LinuxLinux6.12.93 <= 6.12.*unaffected
LinuxLinux6.18.35 <= 6.18.*unaffected
LinuxLinux7.0.12 <= 7.0.*unaffected
LinuxLinux7.1 <= *unaffected

Weaknesses

References