Junglewise Threat Intelligence

CVE-2026-53307: Linux Kernel crash via empty pinmux property in pinctrl

CVE-2026-53307 · Severity: info · Published 2026-06-26

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's pin configuration subsystem, which manages how hardware pins are assigned to different functions. If a specific configuration property is empty when the system expects data, it can cause the kernel to crash by accessing invalid memory. This could lead to a system failure or denial of service, impacting the stability of the affected device.

Technical details

A vulnerability exists in the `pinconf_generic_parse_dt_pinmux()` function within `drivers/pinctrl/pinconf-generic.c` of the Linux kernel. The function incorrectly assumes that the 'pinmux' Device Tree property is non-empty if present. When an empty property is encountered, the memory allocator returns a special non-NULL value that, when subsequently accessed, results in a kernel crash. The fix involves validating the length of the 'pinmux' property before proceeding with memory allocation. This issue affects various kernel versions including 6.15 and has been patched in stable releases 6.18.33 and 7.0.10.

Affected products

  • Linux Linux 6.15 to 6.18.33, 7.0.10, 7.1

Timeline

  • 2026-03-17: disclosed: Initial patch authored by Andy Shevchenko
  • 2026-06-26: advisory: CVE-2026-53307 published in NVD dataset

References