I2C Block Transfer Vulnerability in Linux Kernel by The Linux Foundation
CVE-2026-64191
What is CVE-2026-64191?
A vulnerability in the Linux kernel's I2C stub driver could allow a local user to perform unauthorized block transfers exceeding the safe length limits. The issue arises when the transfer length is specified incorrectly, leading to potential buffer overflows. Proper validation of transfer lengths against the defined limits is essential to maintain system integrity. Consequently, developers are advised to implement stringent checks and ensure that transfers with lengths greater than 32 bytes are rejected to prevent data corruption and potential exploits.
Affected Version(s)
Linux 4710317891e4824ce1510a6b5066abbd3e917750 < 7e9072dbd5f2f17934751873450d2c22080ead80
Linux 4710317891e4824ce1510a6b5066abbd3e917750 < 21e87f336ac6303fed54a69b1d0d79a23b25c8d0
Linux 4710317891e4824ce1510a6b5066abbd3e917750 < 3fd225f3e4cd67ec8ddab1afed9da03c7c43537c