CVE-2026-68089: Linux

EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: iio: core: fix uninitialized data in debugfs If *ppos is non-zero then simple_write_to_buffer() will not initialize the start of buf[]. Non zero values for *ppos aren't going to work anyway. Test for them at the start of the function and return -EINVAL.

Affected products

  • Linux Linux: from 6.15, before 6.18.39 (fixed in 6.18.39); from 6.19, before 7.1.4 (fixed in 7.1.4)

Published 2026-08-10. Last modified 2026-08-17.