CVE-2026-64191: i2c: stub: Reject I2C block transfers with invalid length
Published Jul 20, 2026
·Updated
i2c: stub: Reject I2C block transfers with invalid length
Affected Software
11 affected componentsFixes available
Linux Linux kernel
Linux Linux kernel>=2.6.33<5.10.260
Linux Linux kernel>=5.11<5.15.211
Linux Linux kernel>=5.16<6.1.177
Linux Linux kernel>=6.2<6.6.144
Linux Linux kernel>=6.7<6.12.95
Linux Linux kernel>=6.13<6.18.37
Linux Linux kernel>=6.19<7.0.14
Linux Linux kernel=7.1-rc1
Linux Linux kernel=7.1-rc2
Microsoft azl3 kernel 6.6.143.1-1<6.6.150.1-1
6.6.150.1-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.150.1-1
Event History
Jul 20, 2026
CVE Published
via MITRE·04:27 PM
Data Sourced
via MITRE·04:27 PM
DescriptionSeverity
Data Sourced
via Red Hat·05:02 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·05:18 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jul 22, 2026
Data Sourced
via Microsoft·08:02 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:02 AM
Affected Software
Updated
via Microsoft·08:02 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2026-64191?
The severity of CVE-2026-64191 is rated at risk level 24.
2
What does CVE-2026-64191 affect?
CVE-2026-64191 affects the Linux kernel, specifically the I2C subsystem.
3
How do I fix CVE-2026-64191?
To fix CVE-2026-64191, update your Linux kernel to the latest patched version.
4
What is the nature of the vulnerability in CVE-2026-64191?
CVE-2026-64191 is a vulnerability that allows rejection of I2C block transfers with invalid length.
5
How was CVE-2026-64191 resolved?
CVE-2026-64191 was resolved by implementing checks to ensure valid lengths are used for I2C block transfers.