# CVE-2026-53196

## Summary

- **CVE ID:** CVE-2026-53196
- **Severity:** MEDIUM
- **CVSS Score:** 6.8 (CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** Jun 25, 2026
- **Last Modified:** Sep 16, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

USB: serial: io_ti: fix heap overflow in get_manuf_info()

get_manuf_info() reads le16_to_cpu(rom_desc->Size) bytes from the
device I2C EEPROM into a buffer allocated with kmalloc_obj(), which
is sizeof(struct edge_ti_manuf_descriptor) = 10 bytes.

The Size field comes from the device and is only validated (in
check_i2c_image()) to make sure the descriptor fits within
TI_MAX_I2C_SIZE (16384 bytes), not against the destination buffer size.
A malicious USB device can therefore set Size to any value up to 16377,
causing a heap overflow of up to 16367 bytes when plugged into a host
running this driver.

valid_csum() is called after read_rom() and also iterates
buffer[0..Size-1], compounding the out-of-bounds access.

Fix by rejecting descriptors with unexpected length before calling
read_rom().

[ johan: amend commit message; also check for short descriptors ]

## Affected Products

- Linux — Linux (1da177e4c3f41524e886b7f1b8a0c1fc7321cac2)
- Linux — Linux (2.6.12)
- Linux — Linux (0)
- Linux — Linux (5.10.259)
- Linux — Linux (5.15.210)
- Linux — Linux (6.1.176)
- Linux — Linux (6.6.143)
- Linux — Linux (6.12.94)
- Linux — Linux (6.18.36)
- Linux — Linux (7.0.13)
- Linux — Linux (7.1)

## References

- [CNA](https://git.kernel.org/stable/c/e168db91442b94e64fa82a7dd297983d48ea5cc0)
- [CNA](https://git.kernel.org/stable/c/561edb021486e6723d841926aa4b48097da06190)
- [CNA](https://git.kernel.org/stable/c/cfd634f6dfd40c49a84f9bddc2867a80e2e2623a)
- [CNA](https://git.kernel.org/stable/c/d92f17af7097d10bdeddf26f66f34b354104b277)
- [CNA](https://git.kernel.org/stable/c/b849f30d1a9e66aae6b715aaef66e427390cb081)
- [CNA](https://git.kernel.org/stable/c/f96cf7bf9fbf15d7fcf0c91fec47ba8a010369ea)
- [CNA](https://git.kernel.org/stable/c/d214d2341d4f9f447e36a7d012cdf6a6631a55f1)
- [CNA](https://git.kernel.org/stable/c/183c1076eca43bbb3e7bdf597456f91d81c73e74)
- [redhat-SADP](https://access.redhat.com/security/cve/CVE-2026-53196)
- [redhat-SADP](https://bugzilla.redhat.com/show_bug.cgi?id=2492750)
- [redhat-SADP](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53196.json)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:61887)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:65712)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:65708)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:65710)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:65711)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:65709)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:67114)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:67723)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:67721)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.27%
- **EPSS Percentile:** 19.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._