PT-2026-52242 · Linux+1 · Linux Kernel+1

CVE-2026-53146

·

Published

2026-05-26

·

Updated

2026-09-07

CVSS v3.1

7.1

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the thunderbolt component where the tb xdomain copy() function copies req->response size bytes from the received packet buffer without considering the actual frame size. If a short response is received, the system reads beyond the valid frame data in the DMA (Direct Memory Access) pool buffer, potentially accessing stale data from previous transactions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-90590
BDU:2026-14007
CVE-2026-53146
ECHO-1C14-FF79-B2F0
OPENSUSE-SU-2026:21555-1
SUSE-SU-2026:23066-1
SUSE-SU-2026:23068-1
SUSE-SU-2026:23193-1
SUSE-SU-2026:23194-1
SUSE-SU-2026:23221-1
SUSE-SU-2026:23231-1
SUSE-SU-2026:23237-1
SUSE-SU-2026:23241-1
SUSE-SU-2026:23244-1
SUSE-SU-2026:3130-1
SUSE-SU-2026:3166-1
SUSE-SU-2026:3594-1
USN-8637-1
USN-8726-1
USN-8728-1

Affected Products

Linux Kernel
Ubuntu