Infinite loop in Linux kernel - CVE-2026-53336
Published: July 2, 2026
Vulnerability details
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to an infinite loop in the onie-tlv nvmem layout driver when parsing EEPROM entries with unknown types. A local attacker can provide a crafted EEPROM image containing a vendor-specific or otherwise unknown TLV entry to cause a denial of service.
Affected software
Ubuntu
linux (Ubuntu package)
linux-gcp-7.0 (Ubuntu package)
linux-oem-7.0 (Ubuntu package)
How to mitigate CVE-2026-53336
linux (Ubuntu package) - addressed in versions 7.0.0-31.31, 7.0.0-31.31.1, 7.0.0-31.31~24.04.1, 7.0.0-1006.7, 7.0.0-1011.11~24.04.1, 7.0.0-1012.12, 7.0.0-1012.12~24.04.1
linux-gcp-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-oem-7.0 (Ubuntu package) - update to 7.0.0-1013.13
External References
- https://git.kernel.org/stable/c/033d498b0f473c6456be5f885be172024ad84972
- https://git.kernel.org/stable/c/4a4d21f531ccf5bb333d99b620e0d66551f3652c
- https://git.kernel.org/stable/c/4f27eb01619c36cc8e3ce9a2a9af97f145f5d1c6
- https://git.kernel.org/stable/c/ea41020b9018e31c2ea7e9d89021e3e6d7470883
- https://git.kernel.org/stable/c/fd47edeabadfaa75422009dc5894e92c4c697517