CVE-2026-31627
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/04/2026
Last modified:
27/04/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
i2c: s3c24xx: check the size of the SMBUS message before using it<br />
<br />
The first byte of an i2c SMBUS message is the size, and it should be<br />
verified to ensure that it is in the range of 0..I2C_SMBUS_BLOCK_MAX<br />
before processing it.<br />
<br />
This is the same logic that was added in commit a6e04f05ce0b ("i2c:<br />
tegra: check msg length in SMBUS block read") to the i2c tegra driver.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 3.10.1 (including) | 6.6.136 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.12.83 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (including) | 6.18.24 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (including) | 6.19.14 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 7.0 (including) | 7.0.1 (excluding) |
| cpe:2.3:o:linux:linux_kernel:3.10:-:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/377fae22a137b6b89f3f32399a58c52cf2325416
- https://git.kernel.org/stable/c/71b3c316b22c555d2769126a92b1244b15a9750d
- https://git.kernel.org/stable/c/aaaaec39ddbcd06770dca7f1adebc3b1242ebe7b
- https://git.kernel.org/stable/c/c0128c7157d639a931353ea344fb44aad6d6e17a
- https://git.kernel.org/stable/c/d87d5620125a03b1eadbd5df39748215d3db7ddb
- https://git.kernel.org/stable/c/fa00738ab30b07db1a43b9c85fc56b8cc3b7d197



