Improper input validation in Linux kernel - CVE-2026-53045
Published: June 25, 2026
Vulnerability identifier: #VU135294
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-53045
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vendor: Linux Foundation
Affected software:
Linux kernel
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in the tegra124 emc timing change logic when processing memory timing settings. A local user can provide a timing configuration with an incorrect DLL state check to cause a denial of service.
How to mitigate CVE-2026-53045
Install security update from vendor's repository.
Sources
- https://git.kernel.org/stable/c/05f138fc7e27ee8e7a83ccf966c3fa26cda44dda
- https://git.kernel.org/stable/c/1793249c067a4b28e1aba0ad0e4d73aa9f9e165a
- https://git.kernel.org/stable/c/1ebbbef47d11cc90219c081492ccf995aaa3e9b3
- https://git.kernel.org/stable/c/2369b1831161356e1bcb51385d3e532dc4fe2771
- https://git.kernel.org/stable/c/7e19e72f306484996c52ff96cc92f69b78ed5435
- https://git.kernel.org/stable/c/9597ab9a8296ab337e6820f8a717ff621078b632
- https://git.kernel.org/stable/c/a85967331144fde9300be38bb44d2558eb6b742e
- https://git.kernel.org/stable/c/db0ae80865b515cc0b705c85877ec00f7eebe9fe