0.0
NA
CVE-2026-72481
iio: magnetometer: ak8975: fix potential kernel stack memory leak
Description

In the Linux kernel, the following vulnerability has been resolved: iio: magnetometer: ak8975: fix potential kernel stack memory leak Currently in the AK8975 driver there are four instances where potential uninitialized kernel stack memory leaks can occur. If i2c_smbus_read_i2c_block_data_or_emulated() returns a value less than the size of the buffer, uninitialized bytes are retained in the buffer and later the buffer is passed on to IIO buffers, potentially leaking memory to userspace. Fix this by adding checks whether the return value of the function is equal to the size of the buffer and subsequently if the value is lesser than zero to distinguish from a returned error code.

INFO

Published Date :

Aug. 15, 2026, 6:22 a.m.

Last Modified :

Aug. 17, 2026, 6:19 a.m.

Remotely Exploit :

No

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-72481 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Linux linux_kernel
Solution
Address kernel stack memory leaks by validating function return values.
  • Ensure return values match buffer size.
  • Check for negative return values.
  • Apply kernel patch for AK8975 driver.
  • Validate memory handling in IIO buffers.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-72481 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-72481 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-72481 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-72481 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Aug. 17, 2026

    Action Type Old Value New Value
    Changed Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': 'bc11ca4a0b84a2f2ebaca2614b92998738d13b1e', 'lessThan': '12848f4ded022963944c063e09a192549a4dad1e', 'versionType': 'git'}, {'status': 'affected', 'version': 'bc11ca4a0b84a2f2ebaca2614b92998738d13b1e', 'lessThan': 'a9cf46054f81972f8c0f1dc2a79d2a141999dbce', 'versionType': 'git'}, {'status': 'affected', 'version': 'bc11ca4a0b84a2f2ebaca2614b92998738d13b1e', 'lessThan': '9f920550abacedc7fc3163dea65ac2a7d0b0765d', 'versionType': 'git'}, {'status': 'affected', 'version': 'bc11ca4a0b84a2f2ebaca2614b92998738d13b1e', 'lessThan': '8cf346074533356d67a6a6a43a192328ad341f11', 'versionType': 'git'}, {'status': 'affected', 'version': 'bc11ca4a0b84a2f2ebaca2614b92998738d13b1e', 'lessThan': 'b974566803bceb72f0b9b5f1d7270b79ba963766', 'versionType': 'git'}, {'status': 'affected', 'version': 'bc11ca4a0b84a2f2ebaca2614b92998738d13b1e', 'lessThan': '3d57672119525c59ed73ea21accb001ccbcd6cfd', 'versionType': 'git'}, {'status': 'affected', 'version': 'bc11ca4a0b84a2f2ebaca2614b92998738d13b1e', 'lessThan': 'fb27ebf81136e796c7b719303ef6fd7e1ae5d488', 'versionType': 'git'}, {'status': 'affected', 'version': 'bc11ca4a0b84a2f2ebaca2614b92998738d13b1e', 'lessThan': 'a9a00d727b7bbc5e913a919530a9dd468935bf95', 'versionType': 'git'}], 'programFiles': ['drivers/iio/magnetometer/ak8975.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '4.7'}, {'status': 'unaffected', 'version': '0', 'lessThan': '4.7', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.10.261', 'versionType': 'semver', 'lessThanOrEqual': '5.10.*'}, {'status': 'unaffected', 'version': '5.15.212', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/iio/magnetometer/ak8975.c'], 'defaultStatus': 'affected'}] [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': 'bc11ca4a0b84a2f2ebaca2614b92998738d13b1e', 'lessThan': '12848f4ded022963944c063e09a192549a4dad1e', 'versionType': 'git'}, {'status': 'affected', 'version': 'bc11ca4a0b84a2f2ebaca2614b92998738d13b1e', 'lessThan': 'a9cf46054f81972f8c0f1dc2a79d2a141999dbce', 'versionType': 'git'}, {'status': 'affected', 'version': 'bc11ca4a0b84a2f2ebaca2614b92998738d13b1e', 'lessThan': '9f920550abacedc7fc3163dea65ac2a7d0b0765d', 'versionType': 'git'}, {'status': 'affected', 'version': 'bc11ca4a0b84a2f2ebaca2614b92998738d13b1e', 'lessThan': '8cf346074533356d67a6a6a43a192328ad341f11', 'versionType': 'git'}, {'status': 'affected', 'version': 'bc11ca4a0b84a2f2ebaca2614b92998738d13b1e', 'lessThan': 'b974566803bceb72f0b9b5f1d7270b79ba963766', 'versionType': 'git'}, {'status': 'affected', 'version': 'bc11ca4a0b84a2f2ebaca2614b92998738d13b1e', 'lessThan': '3d57672119525c59ed73ea21accb001ccbcd6cfd', 'versionType': 'git'}, {'status': 'affected', 'version': 'bc11ca4a0b84a2f2ebaca2614b92998738d13b1e', 'lessThan': 'fb27ebf81136e796c7b719303ef6fd7e1ae5d488', 'versionType': 'git'}, {'status': 'affected', 'version': 'bc11ca4a0b84a2f2ebaca2614b92998738d13b1e', 'lessThan': 'a9a00d727b7bbc5e913a919530a9dd468935bf95', 'versionType': 'git'}], 'programFiles': ['drivers/iio/magnetometer/ak8975.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '4.7'}, {'status': 'unaffected', 'version': '0', 'lessThan': '4.7', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.10.261', 'versionType': 'semver', 'lessThanOrEqual': '5.10.*'}, {'status': 'unaffected', 'version': '5.15.212', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/iio/magnetometer/ak8975.c'], 'defaultStatus': 'affected'}]
  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Aug. 15, 2026

    Action Type Old Value New Value
    Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': 'bc11ca4a0b84a2f2ebaca2614b92998738d13b1e', 'lessThan': '12848f4ded022963944c063e09a192549a4dad1e', 'versionType': 'git'}, {'status': 'affected', 'version': 'bc11ca4a0b84a2f2ebaca2614b92998738d13b1e', 'lessThan': 'a9cf46054f81972f8c0f1dc2a79d2a141999dbce', 'versionType': 'git'}, {'status': 'affected', 'version': 'bc11ca4a0b84a2f2ebaca2614b92998738d13b1e', 'lessThan': '9f920550abacedc7fc3163dea65ac2a7d0b0765d', 'versionType': 'git'}, {'status': 'affected', 'version': 'bc11ca4a0b84a2f2ebaca2614b92998738d13b1e', 'lessThan': '8cf346074533356d67a6a6a43a192328ad341f11', 'versionType': 'git'}, {'status': 'affected', 'version': 'bc11ca4a0b84a2f2ebaca2614b92998738d13b1e', 'lessThan': 'b974566803bceb72f0b9b5f1d7270b79ba963766', 'versionType': 'git'}, {'status': 'affected', 'version': 'bc11ca4a0b84a2f2ebaca2614b92998738d13b1e', 'lessThan': '3d57672119525c59ed73ea21accb001ccbcd6cfd', 'versionType': 'git'}, {'status': 'affected', 'version': 'bc11ca4a0b84a2f2ebaca2614b92998738d13b1e', 'lessThan': 'fb27ebf81136e796c7b719303ef6fd7e1ae5d488', 'versionType': 'git'}, {'status': 'affected', 'version': 'bc11ca4a0b84a2f2ebaca2614b92998738d13b1e', 'lessThan': 'a9a00d727b7bbc5e913a919530a9dd468935bf95', 'versionType': 'git'}], 'programFiles': ['drivers/iio/magnetometer/ak8975.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '4.7'}, {'status': 'unaffected', 'version': '0', 'lessThan': '4.7', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.10.261', 'versionType': 'semver', 'lessThanOrEqual': '5.10.*'}, {'status': 'unaffected', 'version': '5.15.212', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/iio/magnetometer/ak8975.c'], 'defaultStatus': 'affected'}]
    Added Description In the Linux kernel, the following vulnerability has been resolved: iio: magnetometer: ak8975: fix potential kernel stack memory leak Currently in the AK8975 driver there are four instances where potential uninitialized kernel stack memory leaks can occur. If i2c_smbus_read_i2c_block_data_or_emulated() returns a value less than the size of the buffer, uninitialized bytes are retained in the buffer and later the buffer is passed on to IIO buffers, potentially leaking memory to userspace. Fix this by adding checks whether the return value of the function is equal to the size of the buffer and subsequently if the value is lesser than zero to distinguish from a returned error code.
    Added Reference https://git.kernel.org/stable/c/12848f4ded022963944c063e09a192549a4dad1e
    Added Reference https://git.kernel.org/stable/c/3d57672119525c59ed73ea21accb001ccbcd6cfd
    Added Reference https://git.kernel.org/stable/c/8cf346074533356d67a6a6a43a192328ad341f11
    Added Reference https://git.kernel.org/stable/c/9f920550abacedc7fc3163dea65ac2a7d0b0765d
    Added Reference https://git.kernel.org/stable/c/a9a00d727b7bbc5e913a919530a9dd468935bf95
    Added Reference https://git.kernel.org/stable/c/a9cf46054f81972f8c0f1dc2a79d2a141999dbce
    Added Reference https://git.kernel.org/stable/c/b974566803bceb72f0b9b5f1d7270b79ba963766
    Added Reference https://git.kernel.org/stable/c/fb27ebf81136e796c7b719303ef6fd7e1ae5d488
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.