CVE-2026-53194
Description
In the Linux kernel, the following vulnerability has been resolved:
USB: serial: kl5kusb105: fix bulk-out buffer overflow
klsi_105_prepare_write_buffer() is called by the generic write path with the bulk-out buffer and its size (bulk_out_size, 64 bytes). It stores a two-byte length header at the start of the buffer and copies the payload from the write fifo starting at buf + KLSI_HDR_LEN, but passes the full buffer size as the number of bytes to copy:
count = kfifo_out_locked(&port->write_fifo, buf + KLSI_HDR_LEN, size, &port->lock);
When the fifo holds at least size bytes, size bytes are copied starting two bytes into the size-byte buffer, writing KLSI_HDR_LEN bytes past its end. Copy at most size - KLSI_HDR_LEN bytes instead, leaving room for the header as safe_serial already does.
Writing bulk_out_size or more bytes to the tty triggers a slab out-of-bounds write, observed with KASAN by emulating the device with dummy_hcd and raw-gadget:
BUG: KASAN: slab-out-of-bounds in kfifo_copy_out+0x83/0xc0 Write of size 64 at addr ffff888112c62202 by task python3 kfifo_copy_out klsi_105_prepare_write_buffer [kl5kusb105] usb_serial_generic_write_start [usbserial] Allocated by task 139: usb_serial_probe [usbserial] The buggy address is located 2 bytes inside of allocated 64-byte region
The out-of-bounds write no longer occurs with this change applied.
Affected products
35cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=2.6.35,<5.10.259
- cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.1:rc7:*:*:*:*:*:*
- (no CPE)
- osv-coords26 versionspkg:apk/chainguard/linux-aws-6.12pkg:apk/chainguard/linux-aws-6.18pkg:apk/chainguard/linux-azure-6.18pkg:apk/chainguard/linux-gcp-6.12pkg:apk/chainguard/linux-gcp-6.18pkg:apk/chainguard/linux-gcp-6.18-bootc-boot-installedpkg:apk/chainguard/linux-qemu-6.12pkg:apk/chainguard/linux-qemu-6.18pkg:apk/chainguard/linux-qemu-6.18-bootc-boot-installedpkg:apk/chainguard/linux-qemu-melangepkg:apk/chainguard/linux-vmware-6.12pkg:apk/chainguard/linux-vmware-6.18pkg:linux/kernelpkg:rpm/opensuse/dtb-aarch64&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-64kb&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-azure&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-default&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-default-base&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-docs&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-kvmsmall&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-obs-build&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-obs-qa&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-rt&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-source&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-syms&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-zfcpdump&distro=openSUSE%20Leap%2016.0
< 6.12.95-r0+ 25 more
- (no CPE)range: < 6.12.95-r0
- (no CPE)range: < 6.18.38-r0
- (no CPE)range: < 6.18.38-r0
- (no CPE)range: < 6.12.95-r0
- (no CPE)range: < 6.18.38-r0
- (no CPE)range: < 6.18.38-r0
- (no CPE)range: < 6.12.95-r0
- (no CPE)range: < 6.18.38-r0
- (no CPE)range: < 6.18.38-r0
- (no CPE)range: < 6.18.38-r0
- (no CPE)range: < 6.12.95-r0
- (no CPE)range: < 6.18.38-r0
- (no CPE)range: >= 2.6.35, < 5.10.259
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1.160000.2.17
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1
Patches
Vulnerability mechanics
References
11- git.kernel.org/stable/c/0a57320f71941d4e0b1307453c9a1f0939afe666nvdPatch
- git.kernel.org/stable/c/14147b7963685957839c76ba8094924e22777d79nvdPatch
- git.kernel.org/stable/c/372f33ebed747d91870f57c0a2e62884a870bffanvdPatch
- git.kernel.org/stable/c/60af1fd82983c26604102e63a3fcc822c186ccebnvdPatch
- git.kernel.org/stable/c/70d86e355c564b5510fde61361df014f5476c83envdPatch
- git.kernel.org/stable/c/96d47e40bf9db4a9efd5c8fb53287a508d165f14nvdPatch
- git.kernel.org/stable/c/a1288cd700f721c1a119c4f1e8efa234e59caadanvdPatch
- git.kernel.org/stable/c/bde742b076cbe26ecc89c8c68c76ae076a524d02nvdPatch
- access.redhat.com/security/cve/CVE-2026-53194nvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53194.jsonnvdThird Party Advisory
News mentions
0No linked articles in our index yet.