Off-by-one in Linux kernel - CVE-2026-53306
Published: June 29, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in hvc_iucv_get_private() in the hvc_iucv driver when handling a device index equal to the number of configured devices. A local user can trigger an off-by-one access to cause a denial of service.
The issue occurs because the bounds check permits access to hvc_iucv_table[8] when hvc_iucv_devices is 8.
How to mitigate CVE-2026-53306
Sources
- https://git.kernel.org/stable/c/11207e42a332eb8bbcb9fe74df9edd2a807c5607
- https://git.kernel.org/stable/c/3104a3f40feb107f77d7116ad9bf6c210ab7babf
- https://git.kernel.org/stable/c/3d3b89e6ab93bdd0efd45828bda6b0e61cc46dff
- https://git.kernel.org/stable/c/484357dff256c816d9466bda35eb765685e4dc86
- https://git.kernel.org/stable/c/a76511bc654819425d3b15e77b523d7f9d81f064
- https://git.kernel.org/stable/c/f1dc8e72de9aabe5d96767a4e97219ac26b79fe5
- https://git.kernel.org/stable/c/f2a880e802ad12d1e38039d1334fb1475d0f5241
- https://git.kernel.org/stable/c/fed8b8f33a46db0ee2efdb000f4f630c86ed8ca4