PT-2026-52290 · Linux · Linux Kernel

·

CVE-2026-53194

·

Published

2026-06-08

·

Updated

2026-09-07

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A slab out-of-bounds write exists in the kl5kusb105 USB serial driver. The function klsi 105 prepare write buffer() incorrectly handles the bulk-out buffer by storing a two-byte length header at the start and then attempting to copy the full buffer size from the write fifo starting at an offset. This results in writing KLSI HDR LEN bytes beyond the end of the allocated buffer when the fifo contains enough data. This issue is triggered when writing bulk out size or more bytes to the tty.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Heap Based Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14029
CVE-2026-53194
ECHO-0BB0-0C4E-105D
OESA-2026-2929
OESA-2026-2930
OESA-2026-3454
OESA-2026-3455
OPENSUSE-SU-2026:21388-1
SUSE-SU-2026:22742-1
SUSE-SU-2026:22769-1
SUSE-SU-2026:22812-1
SUSE-SU-2026:22835-1
SUSE-SU-2026:23193-1
SUSE-SU-2026:23194-1
SUSE-SU-2026:23241-1
SUSE-SU-2026:23244-1
SUSE-SU-2026:2914-1
SUSE-SU-2026:3130-1
SUSE-SU-2026:3166-1
USN-8726-1
USN-8727-1
USN-8728-1

Affected Products

Linux Kernel