SB20260626183 - Integer underflow in Linux kernel misc driver
Published: June 26, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Integer underflow (CVE-ID: CVE-2026-53159)
CWE-ID: CWE-191 - Integer underflow
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a local user to corrupt a DMA address.
The vulnerability exists due to an integer underflow in fastrpc_get_args() when processing a user-provided pointer that falls in a gap before a returned VMA. A local user can supply a crafted pointer value to corrupt a DMA address.
The corrupted DMA address is sent to the DSP.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/2d0f47e27c1fa718b29c69aa7c96a2c5161bc2c2
- https://git.kernel.org/stable/c/464c6ad2aa16e1e1df9d559289199356493d1e00
- https://git.kernel.org/stable/c/53e06f8a3c2b085c31bf1284e2ebcb8036e99625
- https://git.kernel.org/stable/c/708c17b52c60fe7a57e73b495bdee50f58feb48c
- https://git.kernel.org/stable/c/7ba7b30ddb04646d4d638f4d8c4718a304bbbddd
- https://git.kernel.org/stable/c/d3e26df2e8eb361e6bef096b2fd565476a1f14c4
- https://git.kernel.org/stable/c/e69e306a4cccb40a73511350cb280825a556ce3c