High severity7.1NVD Advisory· Published Jul 24, 2026· Updated Aug 12, 2026
CVE-2026-64237
CVE-2026-64237
Description
In the Linux kernel, the following vulnerability has been resolved:
Input: elan_i2c - validate firmware size before use
Ensure that the firmware file is large enough to contain the expected number of pages and the signature (which resides at the end of the firmware blob) before accessing them to prevent potential out-of-bounds reads.
Affected products
8(expand)+ 6 more
- (no CPE)
- cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=4.0,<5.10.259
- cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
8- git.kernel.org/stable/c/331d49b4e1c9efe4479bbd22922dfcdd8c64be7bnvdPatch
- git.kernel.org/stable/c/3b37190ad3ded3a15fb1dbfc4f26df520a3e59bbnvdPatch
- git.kernel.org/stable/c/47b52b98edfe34d0249e72f815215ef24311c3a3nvdPatch
- git.kernel.org/stable/c/48b0aa9c08a3ac8e0c0345b7ca581f552324e460nvdPatch
- git.kernel.org/stable/c/76b0d0baa9ae9c60e726bbe1b6ff0bec2c993634nvdPatch
- git.kernel.org/stable/c/bf769358419e00344c1b16fa034d058f563d46a1nvdPatch
- git.kernel.org/stable/c/c2c3b33b3c0bf2c9427c0926817ef5ffac50de6fnvdPatch
- git.kernel.org/stable/c/d97baee9590edf303b3eca432e61de9320834fe1nvdPatch
News mentions
1- Linux Kernel: 25 Vulnerabilities Across Subsystems Addressed in Coordinated July 2026 DisclosureVypr Intelligence · Jul 25, 2026