Description
In the Linux kernel, the following vulnerability has been resolved:

iio: accel: mma8452: handle I2C read error(s) in mma8452_read()

Currently, If i2c_smbus_read_i2c_block_data() fails but
mma8452_set_runtime_pm_state() succeeds, mma8452_read() returns 0.

As a result, the caller mma8452_read_raw() assumes the read was
successful and proceeds to use a buffer containing uninitialized
stack memory.

Add proper checking of the I2C read return value and propagate errors
to the caller.
Published: 2026-08-15
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Linux kernel mma8452 driver contains a flaw where an I2C read failure is ignored if runtime power management succeeds. Consequently, mma8452_read() returns success, and the caller mma8452_read_raw() interprets the data as valid while actually using uninitialized stack memory. This can expose stale memory content, potentially leaking sensitive data or causing a crash. The weakness is an unchecked return value leading to use of uninitialized data (CWE‑252 and CWE‑457).

Affected Systems

All Linux kernel builds that incorporate the mma8452 IIO driver without the recent fix are affected. The vulnerability impacts the Linux kernel’s acceler­ator driver for the mma8452 sensor, which is used in a variety of embedded devices such as smartphones, tablets, and IoT boards. No specific kernel version numbers are listed in the CNA data, so any kernel containing the unpatched mma8452 driver is vulnerable.

Risk and Exploitability

The CVSS and EPSS metrics are not supplied; however, the flaw can lead to information disclosure or denial of service for a local attacker with privileges to invoke the mma8452_read_raw() interface. The likely attack vector is through local use of the IIO subsystem; an adversary can trigger the failing I2C read by causing sensor reset or bad communication, resulting in use of garbage data. Because the vulnerability is only present in the kernel's device driver, exploitation requires the attacker to have access to the I/O interface, making it a moderate to high risk in environments where the mma8452 sensor is exposed to untrusted users.

Generated by OpenCVE AI on August 15, 2026 at 12:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Linux kernel to the newest release that includes the mma8452 driver fix, or apply the upstream patch that adds proper I2C error handling.
  • If an immediate kernel upgrade is not possible, restrict or disable the mma8452 device by removing it from the IIO subsystem (e.g., using modprobe -r mma8452 or disabling via sysfs) to prevent uninitialized memory usage.
  • Audit other kernel drivers for similar unchecked I2C return values and apply corrective coding practices to enforce error checking on hardware interactions.

Generated by OpenCVE AI on August 15, 2026 at 12:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 15 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-252
CWE-457

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: iio: accel: mma8452: handle I2C read error(s) in mma8452_read() Currently, If i2c_smbus_read_i2c_block_data() fails but mma8452_set_runtime_pm_state() succeeds, mma8452_read() returns 0. As a result, the caller mma8452_read_raw() assumes the read was successful and proceeds to use a buffer containing uninitialized stack memory. Add proper checking of the I2C read return value and propagate errors to the caller.
Title iio: accel: mma8452: handle I2C read error(s) in mma8452_read()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-15T05:57:18.324Z

Reserved: 2026-08-09T03:40:39.935Z

Link: CVE-2026-72479

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:22:22.093

Modified: 2026-08-15T06:22:22.093

Link: CVE-2026-72479

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-15T12:30:07Z

Weaknesses
  • CWE-252

    Unchecked Return Value

  • CWE-457

    Use of Uninitialized Variable