From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D4254363C50 for ; Sat, 15 Aug 2026 06:30:20 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786775422; cv=none; b=JdZNOGQan/bF4wg1sMFze2vLmxxMEOa2V9YLnAbB1Uc8ULd0n+dnQXcxw3EV4HhW7UFdTbyTi4B5YVISCvoNwE4Cn5WoBd/WsoucPiZaQbr7Fe3YYV/GWN/sxLl/DTVInIjdxzznogce07t28azy5RuY95Iv4sis5xxcjAOe6Ko= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786775422; c=relaxed/simple; bh=Dw0qobOI3Uc7+Qp8bw8I/+ZwesCjliLuWwBEdTwvRCA=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=vCo8Ll2+OgtHjcKhivQ4DfCWPjfkxS6Xw3EIoRPM73j76ap+NWFJJWXdQCYvMRDcu82KHzzsZldW8k0JY1VQchUtQoQwT+XdX9iEy0Bh7cz8OohIbltAG2pW8RbIDPGM6ikL+27QleDYF2ZJyPgDGCZd9a3JSUzqy0sq8YiMBPA= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=e11uyH3o; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="e11uyH3o" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 374D31F000E9; Sat, 15 Aug 2026 06:30:20 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1786775420; bh=MpJs8R0qWZGhSP8KE/CVf3ftpovQx9k5lEAtWqRhEgA=; h=From:To:Cc:Subject:Date:Reply-To; b=e11uyH3oc9ib5Nv+H8FvLa1+aX0TtH4sZPBTkkZgiMFPvtiLf7z38/jCJACMh00jl 5CJUzrs7gipFrRAZx/6E3lma2XVgF1O3+sz/aMy/z1jL/hAr7YvcM1othSIyffVKx4 6sPCmTF9mK/Iiz7Z+OpThKGs1+KdmJiUE0XwhomQ= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-72479: iio: accel: mma8452: handle I2C read error(s) in mma8452_read() Date: Sat, 15 Aug 2026 15:09:18 +0900 Message-ID: <2026081536-CVE-2026-72479-5e38@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3504; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=7yJy5wkC6pAVM7toxZ5nNEIYF2tlj4N3jjDWO0IBFaQ=; b=owGbwMvMwCRo6H6F97bub03G02pJDFkNDH+qH/VF73A/fYxVvr3Xp2H3mhob8/fWcTkGh/+Et C7+wqjfEcvCIMjEICumyPJlG8/R/RWHFL0MbU/DzGFlAhnCwMUpABOJ/MAwTyfqmPuXJt7dyTcT d3T+su/PEPgkxTC/4rZFa/D2hyrRr7hbhMr7ZbQcNC4AAA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: iio: accel: mma8452: handle I2C read error(s) in mma8452_read() Currently, If i2c_smbus_read_i2c_block_data() fails but mma8452_set_runtime_pm_state() succeeds, mma8452_read() returns 0. As a result, the caller mma8452_read_raw() assumes the read was successful and proceeds to use a buffer containing uninitialized stack memory. Add proper checking of the I2C read return value and propagate errors to the caller. The Linux kernel CVE team has assigned CVE-2026-72479 to this issue. Affected and fixed versions =========================== Issue introduced in 4.7 with commit 96c0cb2bbfe0a58bd0c37cf34d50a20f9cd75aa8 and fixed in 5.10.261 with commit b488055e81d9faaaf2f8aaff45f9944040ac4493 Issue introduced in 4.7 with commit 96c0cb2bbfe0a58bd0c37cf34d50a20f9cd75aa8 and fixed in 5.15.212 with commit f9ec3f3e9cf27dd06cd3725eeaa44e3ce46be893 Issue introduced in 4.7 with commit 96c0cb2bbfe0a58bd0c37cf34d50a20f9cd75aa8 and fixed in 6.1.178 with commit b4932fc325e84a3233413daf230b043818c8a824 Issue introduced in 4.7 with commit 96c0cb2bbfe0a58bd0c37cf34d50a20f9cd75aa8 and fixed in 6.6.145 with commit eed69f8a10b82989ad732ace0fb43a9fb4e7fe35 Issue introduced in 4.7 with commit 96c0cb2bbfe0a58bd0c37cf34d50a20f9cd75aa8 and fixed in 6.12.97 with commit f3d905ea1e4996d933074481e80d96ecd74a9904 Issue introduced in 4.7 with commit 96c0cb2bbfe0a58bd0c37cf34d50a20f9cd75aa8 and fixed in 6.18.40 with commit 1cddef80a180af74c33d2f26c962ce92b60fded4 Issue introduced in 4.7 with commit 96c0cb2bbfe0a58bd0c37cf34d50a20f9cd75aa8 and fixed in 7.1.5 with commit f3d413e701c5e54bef736b638967724dda880365 Issue introduced in 4.7 with commit 96c0cb2bbfe0a58bd0c37cf34d50a20f9cd75aa8 and fixed in 7.2-rc1 with commit 5bdff291d20c31b365d9ddfe9c426fbfb41da5bb Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-72479 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/iio/accel/mma8452.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/b488055e81d9faaaf2f8aaff45f9944040ac4493 https://git.kernel.org/stable/c/f9ec3f3e9cf27dd06cd3725eeaa44e3ce46be893 https://git.kernel.org/stable/c/b4932fc325e84a3233413daf230b043818c8a824 https://git.kernel.org/stable/c/eed69f8a10b82989ad732ace0fb43a9fb4e7fe35 https://git.kernel.org/stable/c/f3d905ea1e4996d933074481e80d96ecd74a9904 https://git.kernel.org/stable/c/1cddef80a180af74c33d2f26c962ce92b60fded4 https://git.kernel.org/stable/c/f3d413e701c5e54bef736b638967724dda880365 https://git.kernel.org/stable/c/5bdff291d20c31b365d9ddfe9c426fbfb41da5bb