Back to overview

CVE-2026-53146

Description
In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Limit XDomain response copy to actual frame size tb_xdomain_copy() copies req->response_size bytes from the received packet buffer regardless of the actual frame size. When a short response arrives, this reads past the valid frame data in the DMA pool buffer into stale contents from previous transactions. Use the minimum of frame size and expected response size for the copy length.

Metadata

CVE ID
CVE-2026-53146
State
PUBLISHED
Assigner
Linux
Reserved
2026-06-09 07:44 UTC
Published
2026-06-25 08:38 UTC
Last updated
2026-06-25 08:38 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (2)
VendorProductPlatformVersions
Linux Linux cdae7c07e3e3509eaabc18c1640a55dc5b99c179 < c55da494dfb445fb28df3a9d293c2be6a299cd01, cdae7c07e3e3509eaabc18c1640a55dc5b99c179 < 7720654b4842bcdfeb64bc002f6186041849e1e7, cdae7c07e3e3509eaabc18c1640a55dc5b99c179 < 033dfa63bf6be2653441a1dccae4a8313a91bb9d, cdae7c07e3e3509eaabc18c1640a55dc5b99c179 < fc261397295b8ad0654cec747b0ec25ea0011995 …
Linux Linux 4.15, 0 < 4.15, 5.10.259 ≤ 5.10.*, 5.15.210 ≤ 5.15.* …
Back to overview