Junglewise Threat Intelligence

CVE-2026-53150: Linux Kernel Thunderbolt out-of-bounds write in property validator

CVE-2026-53150 · Severity: info · CVSS 6.1 · Published 2026-06-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Thunderbolt driver could allow a local attacker to cause a system crash. The issue occurs when the system processes specifically malformed Thunderbolt device properties, leading to an invalid memory write. This primarily impacts system stability and availability for devices using Thunderbolt or XDomain connections.

Technical details

An integer underflow exists in the Thunderbolt driver's property validator, specifically within the tb_property_entry_valid() function in drivers/thunderbolt/property.c. The validator incorrectly accepts entries with a length of zero for DIRECTORY, DATA, and TEXT types. For TEXT types, this leads to an underflow in the null-termination logic where 'property->length * 4 - 1' results in a write to offset -1 relative to the allocated buffer. An attacker with the ability to provide XDomain property blocks could exploit this to cause a kernel memory corruption or system crash. The issue has been resolved by explicitly rejecting zero-length entries in the validator.

Affected products

  • Linux Linux Kernel 4.15 to 6.13.y

Timeline

  • 2026-05-25: other: Patch authored
  • 2026-06-19: patched: Patch committed to stable tree
  • 2026-06-25: disclosed: CVE published

References