Out-of-Bounds Read Vulnerability in Linux Kernel Affecting elan_i2c Driver
CVE-2026-64237

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
24 July 2026

What is CVE-2026-64237?

A vulnerability has been identified in the elan_i2c driver of the Linux kernel where insufficient validation of firmware size could allow for out-of-bounds reads. This issue occurs when the firmware file is accessed without ensuring its size is adequate to accommodate the expected number of pages and the signature located at the end of the firmware blob. Exploiting this vulnerability may lead to potential system instability or unauthorized access to sensitive information.

Affected Version(s)

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 47b52b98edfe34d0249e72f815215ef24311c3a3

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 331d49b4e1c9efe4479bbd22922dfcdd8c64be7b

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.