Out-of-Bounds Read Vulnerability in Linux Kernel Affecting elan_i2c Driver
CVE-2026-64237
Currently unrated
What is CVE-2026-64237?
A vulnerability has been identified in the elan_i2c driver of the Linux kernel where insufficient validation of firmware size could allow for out-of-bounds reads. This issue occurs when the firmware file is accessed without ensuring its size is adequate to accommodate the expected number of pages and the signature located at the end of the firmware blob. Exploiting this vulnerability may lead to potential system instability or unauthorized access to sensitive information.
Affected Version(s)
Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 47b52b98edfe34d0249e72f815215ef24311c3a3
Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 331d49b4e1c9efe4479bbd22922dfcdd8c64be7b