Back to overview

CVE-2026-53022

Description
In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell-wmi-sysman: bound enumeration string aggregation populate_enum_data() aggregates firmware-provided value-modifier and possible-value strings into fixed 512-byte struct members. The current code bounds each individual source string but then appends every string and separator with raw strcat() and no remaining-space check. Switch the aggregation loops to a bounded append helper and reject enumeration packages whose combined strings do not fit in the destination buffers. [ij: add include]

Metadata

CVE ID
CVE-2026-53022
State
PUBLISHED
Assigner
Linux
Reserved
2026-06-09 07:44 UTC
Published
2026-06-24 16:29 UTC
Last updated
2026-06-24 16:29 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (2)
VendorProductPlatformVersions
Linux Linux e8a60aa7404bfef37705da5607c97737073ac38d < 7b3dc1f764bf24eb99474a5de8173b0b43a8b071, e8a60aa7404bfef37705da5607c97737073ac38d < 75c738d4f27fa18a2a033de153bd40302bde6a66, e8a60aa7404bfef37705da5607c97737073ac38d < ba0843c1955864401295f7ba3b420afe19f2266d, e8a60aa7404bfef37705da5607c97737073ac38d < 5a04f9a36930792f6d64e28d43609e158d09b665 …
Linux Linux 5.11, 0 < 5.11, 5.15.209 ≤ 5.15.*, 6.1.175 ≤ 6.1.* …
Back to overview