CVE-2026-53150

Source
https://cve.org/CVERecord?id=CVE-2026-53150
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-53150.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-53150
Downstream
Related
Published
2026-06-25T08:38:35.531Z
Modified
2026-07-22T18:22:53.500396560Z
Summary
thunderbolt: Reject zero-length property entries in validator
Details

In the Linux kernel, the following vulnerability has been resolved:

thunderbolt: Reject zero-length property entries in validator

tbpropertyentry_valid() accepts entries with length == 0 for DIRECTORY, DATA, and TEXT types. A zero-length TEXT entry passes validation but causes an underflow in the null-termination logic:

property->value.text[property->length * 4 - 1] = '\0';

When property->length is 0 this writes to offset -1 relative to the allocation.

Reject zero-length entries early in the validator since they have no valid representation in the XDomain property protocol.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53150.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
cdae7c07e3e3509eaabc18c1640a55dc5b99c179
Fixed
581c2053ab4dbe27e83c9e62deb4c73aa8dc0c3a
Fixed
35d6c9252a152e756768a26dbf216b9dd9dd8e92
Fixed
99d9dbad1463afb510d42c9714f846361d1b726d
Fixed
5f56bc6bddffe8710ba0ba8844023b5a44ca90e4
Fixed
ca11e7da4fba4b394f69e16448f4463c44c84de6
Fixed
2e0ddac549ebd713eb9f4a15b6496e3440a17d8b
Fixed
3b6e68cb97f725385010264a873e14a3921b6b8a
Fixed
cff8eb65d1eafe7793e54b4d0cf6bf831644630b

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-53150.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.15.0
Fixed
5.10.259
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.210
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.176
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.143
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.94
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.36
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.13

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-53150.json"