PT-2026-52291 · Linux+1 · Linux Kernel+1

CVE-2026-53195

·

Published

2026-06-02

·

Updated

2026-09-07

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A heap overflow exists in the build i2c fw hdr() function. The function allocates a fixed-size buffer but copies a number of bytes determined by the Length variable from the firmware file header without verifying if this value fits within the allocated space. While the check fw sanity() function validates the total firmware size, it does not specifically validate the Length variable, which can be up to 65535 bytes.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Heap Based Buffer Overflow

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14030
CVE-2026-53195
ECHO-E929-8545-02B4
OESA-2026-2930
OESA-2026-3529
OPENSUSE-SU-2026:21555-1
SUSE-SU-2026:23066-1
SUSE-SU-2026:23068-1
SUSE-SU-2026:23193-1
SUSE-SU-2026:23194-1
SUSE-SU-2026:23221-1
SUSE-SU-2026:23231-1
SUSE-SU-2026:23237-1
SUSE-SU-2026:23241-1
SUSE-SU-2026:23244-1
SUSE-SU-2026:3130-1
SUSE-SU-2026:3166-1
USN-8726-1
USN-8727-1
USN-8728-1

Affected Products

Linux Kernel
Ubuntu