I2C Block Transfer Vulnerability in Linux Kernel by The Linux Foundation
CVE-2026-64191

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
20 July 2026

What is CVE-2026-64191?

A vulnerability in the Linux kernel's I2C stub driver could allow a local user to perform unauthorized block transfers exceeding the safe length limits. The issue arises when the transfer length is specified incorrectly, leading to potential buffer overflows. Proper validation of transfer lengths against the defined limits is essential to maintain system integrity. Consequently, developers are advised to implement stringent checks and ensure that transfers with lengths greater than 32 bytes are rejected to prevent data corruption and potential exploits.

Affected Version(s)

Linux 4710317891e4824ce1510a6b5066abbd3e917750 < 7e9072dbd5f2f17934751873450d2c22080ead80

Linux 4710317891e4824ce1510a6b5066abbd3e917750 < 21e87f336ac6303fed54a69b1d0d79a23b25c8d0

Linux 4710317891e4824ce1510a6b5066abbd3e917750 < 3fd225f3e4cd67ec8ddab1afed9da03c7c43537c

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.