CVE-2026-68089

Summary

In the Linux kernel, the following vulnerability has been resolved:

iio: core: fix uninitialized data in debugfs

If *ppos is non-zero then simple_write_to_buffer() will not initialize the start of buf[]. Non zero values for *ppos aren't going to work anyway. Test for them at the start of the function and return -EINVAL.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux6d5dd486c715908b5a6ed02315a15ff044a91025 < e166a8cfb28a3d0da260dd70cae274eb8c7cec8daffected
LinuxLinux6d5dd486c715908b5a6ed02315a15ff044a91025 < 89fbd3e32dffb6227f936a9578e6eb4632aa4580affected
LinuxLinux6d5dd486c715908b5a6ed02315a15ff044a91025 < ab92ed206d41fd171ebd37bc46360d9f2140d043affected
LinuxLinux6.15affected
LinuxLinux0 < 6.15unaffected
LinuxLinux6.18.39 <= 6.18.*unaffected
LinuxLinux7.1.4 <= 7.1.*unaffected
LinuxLinux7.2-rc1 <= *unaffected

Weaknesses

References