CVE-2026-53306 PUBLISHED

tty: hvc_iucv: fix off-by-one in number of supported devices

Assigner: Linux
Reserved: 09.06.2026 Published: 26.06.2026 Updated: 26.06.2026

In the Linux kernel, the following vulnerability has been resolved:

tty: hvc_iucv: fix off-by-one in number of supported devices

MAX_HVC_IUCV_LINES == HVC_ALLOC_TTY_ADAPTERS == 8. This is the number of entries in: static struct hvc_iucv_private *hvc_iucv_table[MAX_HVC_IUCV_LINES];

Sometimes hvc_iucv_table[] is limited by: (a) if (num > hvc_iucv_devices) // for error detection or (b) for (i = 0; i < hvc_iucv_devices; i++) // in 2 places (so these 2 don't agree; second one appears to be correct to me.)

hvc_iucv_devices can be 0..8. This is a counter. (c) if (hvc_iucv_devices > MAX_HVC_IUCV_LINES)

If hvc_iucv_devices == 8, (a) allows the code to access hvc_iucv_table[8]. Oops.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 44a01d5ba8a4d543694461cd3e178cfa6b3f221b to 3d3b89e6ab93bdd0efd45828bda6b0e61cc46dff (excl.)
  • affected from 44a01d5ba8a4d543694461cd3e178cfa6b3f221b to 484357dff256c816d9466bda35eb765685e4dc86 (excl.)
  • affected from 44a01d5ba8a4d543694461cd3e178cfa6b3f221b to 11207e42a332eb8bbcb9fe74df9edd2a807c5607 (excl.)
  • affected from 44a01d5ba8a4d543694461cd3e178cfa6b3f221b to fed8b8f33a46db0ee2efdb000f4f630c86ed8ca4 (excl.)
  • affected from 44a01d5ba8a4d543694461cd3e178cfa6b3f221b to a76511bc654819425d3b15e77b523d7f9d81f064 (excl.)
  • affected from 44a01d5ba8a4d543694461cd3e178cfa6b3f221b to 3104a3f40feb107f77d7116ad9bf6c210ab7babf (excl.)
  • affected from 44a01d5ba8a4d543694461cd3e178cfa6b3f221b to f1dc8e72de9aabe5d96767a4e97219ac26b79fe5 (excl.)
  • affected from 44a01d5ba8a4d543694461cd3e178cfa6b3f221b to f2a880e802ad12d1e38039d1334fb1475d0f5241 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 2.6.29 is affected
  • unaffected from 0 to 2.6.29 (excl.)
  • unaffected from 5.10.258 to 5.10.* (incl.)
  • unaffected from 5.15.209 to 5.15.* (incl.)
  • unaffected from 6.1.175 to 6.1.* (incl.)
  • unaffected from 6.6.141 to 6.6.* (incl.)
  • unaffected from 6.12.91 to 6.12.* (incl.)
  • unaffected from 6.18.33 to 6.18.* (incl.)
  • unaffected from 7.0.10 to 7.0.* (incl.)
  • unaffected from 7.1 to * (incl.)

References