Tracker / CVE-2026-53306
CVE-2026-53306
Medium 5.5
In the Linux kernel, the following vulnerability has been resolved: tty: hvc_iucv: fix off-by-one in number of supported devices MAX_HVC_IUCV_LINES == HVC_ALLOC_TTY_ADAPTERS == 8. This is the number of entries in: static struct hvc_iucv_private *hvc_iucv_table[MAX_HVC_IUCV_LINES]; Sometimes hvc_iucv_table[] is limited by: (a) if (num > hvc_iucv_devices) // for error detection or (b) for (i = 0; i < hvc_iucv_devices; i++) // in 2 places (so these 2 don't agree; second one appears to be correct to me.) hvc_iucv_devices can be 0..8. This is a counter. (c) if (hvc_iucv_devices > MAX_HVC_IUCV_LINES) If hvc_iucv_devices == 8, (a) allows the code to access hvc_iucv_table[8]. Oops.
Affected products and versions
| linux | linux_kernel · 2.6.29 → 5.10.258 |
|---|---|
| linux | linux_kernel · 5.11 → 5.15.209 |
| linux | linux_kernel · 5.16 → 6.1.175 |
| linux | linux_kernel · 6.13 → 6.18.33 |
| linux | linux_kernel · 6.19 → 7.0.10 |
| linux | linux_kernel · 6.2 → 6.6.141 |
| linux | linux_kernel · 6.7 → 6.12.91 |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.