Out-of-bounds write in Linux kernel - CVE-2026-64483
Published: July 27, 2026
Vulnerability details
The vulnerability allows an attacker with physical access to cause a denial of service or execute arbitrary code.
The vulnerability exists due to an out-of-bounds read and out-of-bounds write in isight_packet() when processing crafted FireWire isochronous packets from a device on the bus during normal capture. An attacker with physical access can provide a malicious device that reports an oversized sample count to cause a denial of service or execute arbitrary code.
Exploitation requires a malicious or faulty Apple iSight device connected on the FireWire bus.
Affected software
How to mitigate CVE-2026-64483
External References
- https://git.kernel.org/stable/c/24423e0a9251d348c3f1fb0bb0e61b879e1e976c
- https://git.kernel.org/stable/c/29b9667982e4df2ed7744f86b1144f8bb58eb698
- https://git.kernel.org/stable/c/31a01b70bb90e3ef3147f308e2ea899e1d2485ca
- https://git.kernel.org/stable/c/31da82b9676c6b112e7c72c7529e6812b919742a
- https://git.kernel.org/stable/c/3ed2fa1ed8cc65f910b8bbc0be3cc366b30f8478
- https://git.kernel.org/stable/c/57e4d9043afc1eaddee8f50d11def6e65415d273
- https://git.kernel.org/stable/c/8e48a29813df8dd71503800b7acf69c12c035045
- https://git.kernel.org/stable/c/ebbffacda6733dcbcef601b5b523460f8d8b671e