CVE-2026-53387

Source
https://cve.org/CVERecord?id=CVE-2026-53387
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53387.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-53387
Downstream
Published
2026-07-19T11:59:33.888Z
Modified
2026-07-21T03:47:20.882295284Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H CVSS Calculator
Summary
iio: light: veml6075: add bounds check to veml6075_it_ms index
Details

In the Linux kernel, the following vulnerability has been resolved:

iio: light: veml6075: add bounds check to veml6075itms index

veml6075itms has 5 elements but VEML6075CONFIT can yield values 0-7. If it returns a value >= 5, this causes an out-of-bounds array access. Add a bounds check and return -EINVAL if the index is out of range.

The problem values are reserved so should never be read from the register. Hence this is hardening against fault device, missprogramming or bus corruption.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53387.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
3b82f43238aecd73464aeacc9c73407079511533
Fixed
df9127a1d2d748e426c49c8fcd9b6801e4eb743d
Fixed
0a89002737ee34decc20fa232204dbe5fe83e0de
Fixed
f75beebcd5bc9bdc80e0722142e78a6f306214ee
Fixed
e545936e06f1c7173ab41a5f33a77ff43ced3a8d
Fixed
307dc4240bd41852d9e0912921e298160db1c109

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53387.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.8.0
Fixed
6.12.95
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.37
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.14
Type
ECOSYSTEM
Events
Introduced
7.1.0
Fixed
7.1.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53387.json"