CVE-2026-64237
In the Linux kernel, the following vulnerability has been resolved: Input: elan_i2c - validate firmware size before use Ensure that the firmware file is large enough to contain the expected number of pages and the signature (which resides at the end of the firmware blob) before accessing them to prevent potential out-of-bounds reads.
Weakness
In the Linux kernel, the following vulnerability has been resolved: Input: elan_i2c - validate firmware size before use Ensure that the firmware file is large enough to contain the expected number of pages and the signature (which resides at the end of the firmware blob) before accessing them to prevent potential out-of-bounds reads.
Affected products
- linux linux_kernel
References
- https://git.kernel.org/stable/c/331d49b4e1c9efe4479bbd22922dfcdd8c64be7b
- https://git.kernel.org/stable/c/3b37190ad3ded3a15fb1dbfc4f26df520a3e59bb
- https://git.kernel.org/stable/c/47b52b98edfe34d0249e72f815215ef24311c3a3
- https://git.kernel.org/stable/c/48b0aa9c08a3ac8e0c0345b7ca581f552324e460
- https://git.kernel.org/stable/c/76b0d0baa9ae9c60e726bbe1b6ff0bec2c993634
- https://git.kernel.org/stable/c/bf769358419e00344c1b16fa034d058f563d46a1
Find the bug before an attacker does.
Sign in with GitHub and run your first audit in under a minute. The free plan needs no credit card.