CVE-2026-53387
Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
19/07/2026
Última modificación:
29/07/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
iio: light: veml6075: add bounds check to veml6075_it_ms index<br />
<br />
veml6075_it_ms has 5 elements but VEML6075_CONF_IT can yield values 0-7.<br />
If it returns a value >= 5, this causes an out-of-bounds array access.<br />
Add a bounds check and return -EINVAL if the index is out of range.<br />
<br />
The problem values are reserved so should never be read from the<br />
register. Hence this is hardening against fault device, missprogramming<br />
or bus corruption.
Impacto
Puntuación base 3.x
7.10
Gravedad 3.x
ALTA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.8 (incluyendo) | 6.12.95 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (incluyendo) | 6.18.37 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (incluyendo) | 7.0.14 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 7.1 (incluyendo) | 7.1.2 (excluyendo) |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/0a89002737ee34decc20fa232204dbe5fe83e0de
- https://git.kernel.org/stable/c/307dc4240bd41852d9e0912921e298160db1c109
- https://git.kernel.org/stable/c/df9127a1d2d748e426c49c8fcd9b6801e4eb743d
- https://git.kernel.org/stable/c/e545936e06f1c7173ab41a5f33a77ff43ced3a8d
- https://git.kernel.org/stable/c/f75beebcd5bc9bdc80e0722142e78a6f306214ee



