CyberRota Analysis
AI-GeneratedThe vulnerability in the Linux kernel affects the adis16550 IMU driver, where uninitialized stack data in the trigger handler can be leaked to userspace. This stack leak occurs due to the improper initialization of the scan data array, potentially exposing sensitive information. Organizations utilizing affected Linux systems, particularly those relying on the adis16550 driver for IMU data, should prioritize addressing this issue to mitigate the risk of information disclosure.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: iio: imu: adis16550: fix stack leak in trigger handler adis16550_trigger_handler() declares the scan data array on the stack without initializing it. The memcpy() at the bottom fills only the first 28 bytes (TEMP + 6 channels of GYRO/ACCEL data), and iio_push_to_buffers_with_timestamp() writes the s64 timestamp at the 8-byte-aligned offset 32. Bytes 28-31 remain uninitialized stack data which leaks to userspace on ever trigger. Fix this all by just zero-initializing the structure on the stack.