PT-2026-51976 · Linux+2 · Linux Kernel+2

CVE-2026-53082

·

Published

2026-04-10

·

Updated

2026-09-07

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the sixpack receive buf() function where bytes with TTY error flags are not properly skipped. The function iterates through the flags buffer without advancing the data pointer cp, causing the original count to be passed to sixpack decode(). Consequently, sixpack decode() processes bytes that should have been ignored. Because the TTY layer does not guarantee that cp[i] contains a meaningful value when fp[i] is set, this leads to an uninitialized value read reported by KMSAN (Kernel Memory Sanitizer), a tool used to detect uninitialized memory access in the kernel.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Infinite Loop

Access of Uninitialized Pointer

Use of Uninitialized Resource

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-13987
CVE-2026-53082
ECHO-4B3F-1CCF-4D42
OPENSUSE-SU-2026:21555-1
SUSE-SU-2026:23066-1
SUSE-SU-2026:23068-1
SUSE-SU-2026:23221-1
SUSE-SU-2026:23231-1
SUSE-SU-2026:23237-1
USN-8566-1
USN-8567-1
USN-8568-1
USN-8569-1
USN-8574-1
USN-8574-2
USN-8574-3
USN-8575-1
USN-8575-2
USN-8575-3
USN-8576-1
USN-8576-2
USN-8593-1
USN-8595-1
USN-8595-2
USN-8595-3
USN-8596-1
USN-8603-1
USN-8606-1
USN-8607-1
USN-8608-1
USN-8609-1
USN-8610-1
USN-8618-1
USN-8619-1
USN-8620-1
USN-8620-2
USN-8620-3
USN-8620-4
USN-8663-1
USN-8664-1
USN-8665-1
USN-8668-1
USN-8728-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu