CVE-2026-53387

In the Linux kernel, the following vulnerability has been resolved: iio: light: veml6075: add bounds check to veml6075_it_ms index veml6075_it_ms has 5 elements but VEML6075_CONF_IT can yield values 0-7. If it returns a value >= 5, this causes an out-of-bounds array access. Add a bounds check and return -EINVAL if the index is out of range. The problem values are reserved so should never be read from the register. Hence this is hardening against fault device, missprogramming or bus corruption.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

29 Jul 2026, 19:30

Type Values Removed Values Added
CWE CWE-129
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
First Time Linux linux Kernel
Linux
References () https://git.kernel.org/stable/c/0a89002737ee34decc20fa232204dbe5fe83e0de - () https://git.kernel.org/stable/c/0a89002737ee34decc20fa232204dbe5fe83e0de - Patch
References () https://git.kernel.org/stable/c/307dc4240bd41852d9e0912921e298160db1c109 - () https://git.kernel.org/stable/c/307dc4240bd41852d9e0912921e298160db1c109 - Patch
References () https://git.kernel.org/stable/c/df9127a1d2d748e426c49c8fcd9b6801e4eb743d - () https://git.kernel.org/stable/c/df9127a1d2d748e426c49c8fcd9b6801e4eb743d - Patch
References () https://git.kernel.org/stable/c/e545936e06f1c7173ab41a5f33a77ff43ced3a8d - () https://git.kernel.org/stable/c/e545936e06f1c7173ab41a5f33a77ff43ced3a8d - Patch
References () https://git.kernel.org/stable/c/f75beebcd5bc9bdc80e0722142e78a6f306214ee - () https://git.kernel.org/stable/c/f75beebcd5bc9bdc80e0722142e78a6f306214ee - Patch

20 Jul 2026, 15:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.1

19 Jul 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-19 12:16

Updated : 2026-07-29 19:30


NVD link : CVE-2026-53387

Mitre link : CVE-2026-53387

CVE.ORG link : CVE-2026-53387


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-129

Improper Validation of Array Index