CVE-2026-53386

Source
https://cve.org/CVERecord?id=CVE-2026-53386
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53386.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-53386
Downstream
Published
2026-07-19T11:59:33.318Z
Modified
2026-07-21T03:46:28.091475974Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
iio: adc: ti-ads1298: add bounds check to pga_settings index
Details

In the Linux kernel, the following vulnerability has been resolved:

iio: adc: ti-ads1298: add bounds check to pga_settings index

ads1298pgasettings has 7 elements but ADS1298MASKCH_PGA can yield values 0-7. If it yields a value >= 7, this causes an out-of-bounds array access. Add a bounds check and return -EINVAL if the index is out of range.

Note that the remaining value b111 is reserved so should not be seen in a correctly functioning system.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53386.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
00ef7708fa6073a84f6898fdcdfe965d903b0378
Fixed
d5793975fc3b1780ba576812158ef22e3104e60e
Fixed
d08d82d83ed45fd8c001a9df66ad7ebb86c9d6c6
Fixed
abe0854e356b1bb814393ca884cb42b3eb12ce10
Fixed
abd776ded3e256889610595290f6ca46cb6e91ab
Fixed
95e8a48d7a85d4226934020e57815a3316d3a14b

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53386.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.9.0
Fixed
6.12.95
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.37
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.14
Type
ECOSYSTEM
Events
Introduced
7.1.0
Fixed
7.1.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53386.json"