CVE-2026-53148
published 2026-06-25CVE-2026-53148: In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Clamp XDomain response data copy to allocation size…
PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.14%
3.4th percentile
In the Linux kernel, the following vulnerability has been resolved:
thunderbolt: Clamp XDomain response data copy to allocation size
tb_xdp_properties_request() derives the per-packet copy length from
the response header without checking that it fits in the previously
allocated data buffer. A malicious peer can set its length field
larger than the declared data_length, causing memcpy to write past
the kcalloc allocation.
Clamp the per-packet copy length so that the cumulative offset
never exceeds data_len.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= cdae7c07e3e3509eaabc18c1640a55dc5b99c179 < 0b334279a82d79fb4723bd4f614305de1ab69caa | 0b334279a82d79fb4723bd4f614305de1ab69caa |
| linux | linux | >= cdae7c07e3e3509eaabc18c1640a55dc5b99c179 < 6021d39ccd979713b39b980286020d8f9a45efd1 | 6021d39ccd979713b39b980286020d8f9a45efd1 |
| linux | linux | >= cdae7c07e3e3509eaabc18c1640a55dc5b99c179 < 89ae04365e01d5ae4aae83044a8bbd2a9aaf8d0d | 89ae04365e01d5ae4aae83044a8bbd2a9aaf8d0d |
| linux | linux | >= cdae7c07e3e3509eaabc18c1640a55dc5b99c179 < 5db10c8ad8c09f72c847dfeef3d876098257f505 | 5db10c8ad8c09f72c847dfeef3d876098257f505 |
| linux | linux | >= cdae7c07e3e3509eaabc18c1640a55dc5b99c179 < 05a43157676c243c248d1c6d9dcecbe6eba2f35d | 05a43157676c243c248d1c6d9dcecbe6eba2f35d |
| linux | linux | >= cdae7c07e3e3509eaabc18c1640a55dc5b99c179 < fcbd0cdab92838854a5818be7ed8a097164ef6d5 | fcbd0cdab92838854a5818be7ed8a097164ef6d5 |
| linux | linux | >= cdae7c07e3e3509eaabc18c1640a55dc5b99c179 < 906035d5c3784570191d259cbf9a0ac1617852b5 | 906035d5c3784570191d259cbf9a0ac1617852b5 |
| linux | linux | >= cdae7c07e3e3509eaabc18c1640a55dc5b99c179 < 322e93448d908434ae5545660fcbe8f5a7a8e141 | 322e93448d908434ae5545660fcbe8f5a7a8e141 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 4.15 < 5.10.259 | 5.10.259 |
| linux | linux_kernel | >= 5.11 < 5.15.210 | 5.15.210 |
| linux | linux_kernel | >= 5.16 < 6.1.176 | 6.1.176 |
| linux | linux_kernel | >= 6.13 < 6.18.36 | 6.18.36 |
| linux | linux_kernel | >= 6.19 < 7.0.13 | 7.0.13 |
| linux | linux_kernel | >= 6.2 < 6.6.143 | 6.6.143 |
| linux | linux_kernel | >= 6.7 < 6.12.94 | 6.12.94 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel up to 7.0.12 thunderbolt tb_xdp_properties_request buffer overflow (WID-SEC-2026-2077)
vuldb·2026-06-28
CVE-2026-53148 [CRITICAL] Linux Kernel up to 7.0.12 thunderbolt tb_xdp_properties_request buffer overflow (WID-SEC-2026-2077)
A vulnerability was found in Linux Kernel up to 7.0.12. It has been classified as critical. Affected is the function tb_xdp_properties_request of the component thunderbolt. This manipulation causes buffer overflow.
This vulnerability is registered as CVE-2026-53148. The attack requires access to the local network. No exploit is available.
Upgrading the affected component is recommended.
GHSA
In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Clamp XDomain response data copy to allocation size tb_xdp_properties_request() derives the per-packet copy length fr
ghsa_unreviewed·2026-06-25
CVE-2026-53148 In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Clamp XDomain response data copy to allocation size tb_xdp_properties_request() derives the per-packet copy length fr
In the Linux kernel, the following vulnerability has been resolved:
thunderbolt: Clamp XDomain response data copy to allocation size
tb_xdp_properties_request() derives the per-packet copy length from
the response header without checking that it fits in the previously
allocated data buffer. A malicious peer can set its length field
larger than the declared data_length, causing memcpy to write past
the kcalloc allocation.
Clamp the per-packet copy length so that the cumulative offset
never exceeds data_len.
Red Hat
kernel: thunderbolt: Clamp XDomain response data copy to allocation size
vendor_redhat·2026-06-25·CVSS 7.0
CVE-2026-53148 [HIGH] CWE-787 kernel: thunderbolt: Clamp XDomain response data copy to allocation size
kernel: thunderbolt: Clamp XDomain response data copy to allocation size
A flaw was found in the Linux kernel's Thunderbolt driver. A malicious peer can exploit this vulnerability by sending a specially crafted response that causes the system to write data beyond an allocated memory buffer. This out-of-bounds write can lead to memory corruption, which may allow an attacker to cause a denial of service or potentially execute arbitrary code.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/05a43157676c243c248d1c6d9dcecbe6eba2f35dhttps://git.kernel.org/stable/c/0b334279a82d79fb4723bd4f614305de1ab69caahttps://git.kernel.org/stable/c/322e93448d908434ae5545660fcbe8f5a7a8e141https://git.kernel.org/stable/c/5db10c8ad8c09f72c847dfeef3d876098257f505https://git.kernel.org/stable/c/6021d39ccd979713b39b980286020d8f9a45efd1https://git.kernel.org/stable/c/89ae04365e01d5ae4aae83044a8bbd2a9aaf8d0dhttps://git.kernel.org/stable/c/906035d5c3784570191d259cbf9a0ac1617852b5https://git.kernel.org/stable/c/fcbd0cdab92838854a5818be7ed8a097164ef6d5https://access.redhat.com/security/cve/CVE-2026-53148https://bugzilla.redhat.com/show_bug.cgi?id=2492756https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53148.json
2026-06-25
Published