CVE-2026-53150: thunderbolt: Reject zero-length property entries in validator
In the Linux kernel, the following vulnerability has been resolved:
thunderbolt: Reject zero-length property entries in validator
tbpropertyentryvalid() accepts entries with length == 0 for DIRECTORY, DATA, and TEXT types. A zero-length TEXT entry passes validation but causes an underflow in the null-termination logic:
property->value.text[property->length 4 - 1] = '\0';
When property->length is 0 this writes to offset -1 relative to the allocation.
Reject zero-length entries early in the validator since they have no valid representation in the XDomain property protocol.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-53150?
The severity of CVE-2026-53150 is rated at 47.
How do I fix CVE-2026-53150?
To fix CVE-2026-53150, ensure that your Linux kernel is updated to the latest version where the vulnerability has been patched.
What types of entries does CVE-2026-53150 affect?
CVE-2026-53150 affects zero-length property entries of DIRECTORY, DATA, and TEXT types in the Linux kernel.
What happens if a zero-length TEXT entry is validated under CVE-2026-53150?
Validating a zero-length TEXT entry under CVE-2026-53150 can cause an underflow in the Linux kernel.
When was CVE-2026-53150 published?
CVE-2026-53150 was published on June 25, 2026.