CVE-2026-53195: USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr()
In the Linux kernel, the following vulnerability has been resolved:
USB: serial: ioti: fix heap overflow in buildi2cfwhdr()
buildi2cfwhdr() allocates a fixed-size buffer of (161024 - 512) + sizeof(struct tii2cfirmwarerec) bytes, then copies le16tocpu(imgheader->Length) bytes into it without validating that Length fits within the available space after the firmware record header.
imgheader->Length is a le16 from the firmware file and can be up to 65535. checkfwsanity() validates the total firmware size but not imgheader->Length specifically.
Fix by rejecting images where imgheader->Length exceeds the available destination space.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.143.1-1 - Compensating control
In build_i2c_fw_hdr()/check_fw_sanity(), reject firmware images when img_header->Length (le16_to_cpu(img_header->Length)) exceeds the available destination space (the fixed-size buffer size minus the existing offset/headers), so the function does not copy more than fits into the allocated buffer.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-53195?
The severity of CVE-2026-53195 is classified as high with a score of 7.1.
What is the impact of CVE-2026-53195?
CVE-2026-53195 can lead to a heap overflow which may allow an attacker to execute arbitrary code.
In which software is CVE-2026-53195 found?
CVE-2026-53195 affects the Linux kernel, particularly the USB serial io_ti driver.
How do I fix CVE-2026-53195?
To resolve CVE-2026-53195, ensure that your Linux kernel is updated to a version that includes the fix for the heap overflow vulnerability.
What are the affected systems of CVE-2026-53195?
CVE-2026-53195 affects systems running the Linux kernel version that includes the USB serial io_ti driver.