CVE-2026-53387

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/07/2026
Last modified:
29/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> iio: light: veml6075: add bounds check to veml6075_it_ms index<br /> <br /> veml6075_it_ms has 5 elements but VEML6075_CONF_IT can yield values 0-7.<br /> If it returns a value &gt;= 5, this causes an out-of-bounds array access.<br /> Add a bounds check and return -EINVAL if the index is out of range.<br /> <br /> The problem values are reserved so should never be read from the<br /> register. Hence this is hardening against fault device, missprogramming<br /> or bus corruption.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.8 (including) 6.12.95 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (including) 6.18.37 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (including) 7.0.14 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 7.1 (including) 7.1.2 (excluding)