Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-53387

Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
19/07/2026
Última modificación:
29/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> iio: light: veml6075: add bounds check to veml6075_it_ms index<br /> <br /> veml6075_it_ms has 5 elements but VEML6075_CONF_IT can yield values 0-7.<br /> If it returns a value &gt;= 5, this causes an out-of-bounds array access.<br /> Add a bounds check and return -EINVAL if the index is out of range.<br /> <br /> The problem values are reserved so should never be read from the<br /> register. Hence this is hardening against fault device, missprogramming<br /> or bus corruption.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.8 (incluyendo) 6.12.95 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (incluyendo) 6.18.37 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (incluyendo) 7.0.14 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 7.1 (incluyendo) 7.1.2 (excluyendo)