CVE-2026-53119

Source
https://cve.org/CVERecord?id=CVE-2026-53119
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-53119.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-53119
Downstream
Published
2026-06-24T16:30:49.969Z
Modified
2026-06-25T04:05:22.271775252Z
Summary
platform/wmi: use generic driver_override infrastructure
Details

In the Linux kernel, the following vulnerability has been resolved:

platform/wmi: use generic driver_override infrastructure

When a driver is probed through __driverattach(), the bus' match() callback is called without the device lock held, thus accessing the driveroverride field without a lock, which can cause a UAF.

Fix this by using the driver-core driver_override infrastructure taking care of proper locking internally.

Note that calling match() from _driverattach() without the device lock held is intentional. [1]

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53119.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
12046f8c77e0ed6d41beabde0edbb729499c970b
Fixed
13d201bd840d2e2a645ef899f81342cd27ced346
Fixed
2c5507010fc3b8e2bd596c63c88f6ad39a69b1c4
Fixed
4dc755d86deed88789540d960e421124bad4c568
Fixed
8a700b1fc94df4d847a04f14ebc7f8532592b367

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-53119.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.11.0
Fixed
6.12.91
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.33
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.10

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-53119.json"