CVE-2026-53306 is a vulnerability in Linux Kernel
Published on June 26, 2026
tty: hvc_iucv: fix off-by-one in number of supported devices
In the Linux kernel, the following vulnerability has been resolved:
tty: hvc_iucv: fix off-by-one in number of supported devices
MAX_HVC_IUCV_LINES == HVC_ALLOC_TTY_ADAPTERS == 8.
This is the number of entries in:
static struct hvc_iucv_private *hvc_iucv_table[MAX_HVC_IUCV_LINES];
Sometimes hvc_iucv_table[] is limited by:
(a) if (num > hvc_iucv_devices) // for error detection
or
(b) for (i = 0; i < hvc_iucv_devices; i++) // in 2 places
(so these 2 don't agree; second one appears to be correct to me.)
hvc_iucv_devices can be 0..8. This is a counter.
(c) if (hvc_iucv_devices > MAX_HVC_IUCV_LINES)
If hvc_iucv_devices == 8, (a) allows the code to access hvc_iucv_table[8].
Oops.
Products Associated with CVE-2026-53306
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 44a01d5ba8a4d543694461cd3e178cfa6b3f221b and below 3d3b89e6ab93bdd0efd45828bda6b0e61cc46dff is affected.
- Version 44a01d5ba8a4d543694461cd3e178cfa6b3f221b and below 484357dff256c816d9466bda35eb765685e4dc86 is affected.
- Version 44a01d5ba8a4d543694461cd3e178cfa6b3f221b and below 11207e42a332eb8bbcb9fe74df9edd2a807c5607 is affected.
- Version 44a01d5ba8a4d543694461cd3e178cfa6b3f221b and below fed8b8f33a46db0ee2efdb000f4f630c86ed8ca4 is affected.
- Version 44a01d5ba8a4d543694461cd3e178cfa6b3f221b and below a76511bc654819425d3b15e77b523d7f9d81f064 is affected.
- Version 44a01d5ba8a4d543694461cd3e178cfa6b3f221b and below 3104a3f40feb107f77d7116ad9bf6c210ab7babf is affected.
- Version 44a01d5ba8a4d543694461cd3e178cfa6b3f221b and below f1dc8e72de9aabe5d96767a4e97219ac26b79fe5 is affected.
- Version 44a01d5ba8a4d543694461cd3e178cfa6b3f221b and below f2a880e802ad12d1e38039d1334fb1475d0f5241 is affected.
- Version 2.6.29 is affected.
- Before 2.6.29 is unaffected.
- Version 5.10.258, <= 5.10.* is unaffected.
- Version 5.15.209, <= 5.15.* is unaffected.
- Version 6.1.175, <= 6.1.* is unaffected.
- Version 6.6.141, <= 6.6.* is unaffected.
- Version 6.12.91, <= 6.12.* is unaffected.
- Version 6.18.33, <= 6.18.* is unaffected.
- Version 7.0.10, <= 7.0.* is unaffected.
- Version 7.1, <= * is unaffected.