VDB

CVE-2026-53022

CVE-2026-53022 PUBLISHED

Reported by Linux · Published June 24, 2026

In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell-wmi-sysman: bound enumeration string aggregation populate_enum_data() aggregates firmware-provided value-modifier and possible-value strings into fixed 512-byte struct members. The current code bounds each individual source string but then appends every string and separator with raw strcat() and no remaining-space check. Switch the aggregation loops to a bounded append helper and reject enumeration packages whose combined strings do not fit in the destination buffers. [ij: add include]

EPSS 0.12% · 2.4th percentile

Risk Scores

EPSS Score
0.12%
2.4th percentile

Affected Products

VendorProductVersions
LinuxLinuxe8a60aa7404bfef37705da5607c97737073ac38d, e8a60aa7404bfef37705da5607c97737073ac38d, e8a60aa7404bfef37705da5607c97737073ac38d
LinuxLinux5.11, 0, 5.15.209
LinuxLinux7.1, 0, 5.15.209
linuxlinux_kernel5.11, 5.11, 5.11

Timeline

  • Jun 24, 2026 CVE Published
  • Jun 25, 2026 Coalition ESS Score
  • Jun 26, 2026 EPSS Score
  • Aug 7, 2026 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›