Out-of-bounds read in Linux kernel - CVE-2026-53387
Published: July 21, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in the veml6075_request_measurement function when processing the VEML6075_CONF_IT register value. A local user can trigger an out-of-range index value to cause a denial of service.
Exploitation requires fault device behavior, misprogramming, or bus corruption to produce a reserved register value.
Affected software
How to mitigate CVE-2026-53387
External References
- https://git.kernel.org/stable/c/0a89002737ee34decc20fa232204dbe5fe83e0de
- https://git.kernel.org/stable/c/307dc4240bd41852d9e0912921e298160db1c109
- https://git.kernel.org/stable/c/df9127a1d2d748e426c49c8fcd9b6801e4eb743d
- https://git.kernel.org/stable/c/e545936e06f1c7173ab41a5f33a77ff43ced3a8d
- https://git.kernel.org/stable/c/f75beebcd5bc9bdc80e0722142e78a6f306214ee