CVE-2026-53022
Reported by Linux · Published June 24, 2026
In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell-wmi-sysman: bound enumeration string aggregation populate_enum_data() aggregates firmware-provided value-modifier and possible-value strings into fixed 512-byte struct members. The current code bounds each individual source string but then appends every string and separator with raw strcat() and no remaining-space check. Switch the aggregation loops to a bounded append helper and reject enumeration packages whose combined strings do not fit in the destination buffers. [ij: add include]
EPSS 0.12% · 2.4th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | e8a60aa7404bfef37705da5607c97737073ac38d, e8a60aa7404bfef37705da5607c97737073ac38d, e8a60aa7404bfef37705da5607c97737073ac38d |
| Linux | Linux | 5.11, 0, 5.15.209 |
| Linux | Linux | 7.1, 0, 5.15.209 |
| linux | linux_kernel | 5.11, 5.11, 5.11 |
Timeline
- Jun 24, 2026 CVE Published
- Jun 25, 2026 Coalition ESS Score
- Jun 26, 2026 EPSS Score
- Aug 7, 2026 EPSS Score