Answer in brief
CVE-2026-53194 records a High severity (CVSS 7.8) vulnerability in USB: serial: kl5kusb105: fix bulk-out buffer overflow. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-53194 records a High severity (CVSS 7.8) vulnerability in USB: serial: kl5kusb105: fix bulk-out buffer overflow. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=60b3013cdaf3fa8a17243ca46b19db3cbe08d943 <60af1fd82983c26604102e63a3fcc822c186cceb || >=60b3013cdaf3fa8a17243ca46b19db3cbe08d943 <0a57320f71941d4e0b1307453c9a1f0939afe666 || >=60b3013cdaf3fa8a17243ca46b19db3cbe08d943 <14147b7963685957839c76ba8094924e22777d79 || >=60b3013cdaf3fa8a17243ca46b19db3cbe08d943 <a1288cd700f721c1a119c4f1e8efa234e59caada || >=60b3013cdaf3fa8a17243ca46b19db3cbe08d943 <70d86e355c564b5510fde61361df014f5476c83e || >=60b3013cdaf3fa8a17243ca46b19db3cbe08d943 <372f33ebed747d91870f57c0a2e62884a870bffa || >=60b3013cdaf3fa8a17243ca46b19db3cbe08d943 <bde742b076cbe26ecc89c8c68c76ae076a524d02 || >=60b3013cdaf3fa8a17243ca46b19db3cbe08d943 <96d47e40bf9db4a9efd5c8fb53287a508d165f14 | 60af1fd82983c26604102e63a3fcc822c186cceb, 0a57320f71941d4e0b1307453c9a1f0939afe666, 14147b7963685957839c76ba8094924e22777d79, a1288cd700f721c1a119c4f1e8efa234e59caada, 70d86e355c564b5510fde61361df014f5476c83e, 372f33ebed747d91870f57c0a2e62884a870bffa, bde742b076cbe26ecc89c8c68c76ae076a524d02, 96d47e40bf9db4a9efd5c8fb53287a508d165f14 |
| Linux/Linuxgeneric | 2.6.35 | Not reported |
Published upstream
Jun 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jun 25, 2026
In the Linux kernel, the following vulnerability has been resolved: USB: serial: kl5kusb105: fix bulk-out buffer overflow klsi_105_prepare_write_buffer() is called by the generic write path with the bulk-out buffer and its size (bulk_out_size, 64 bytes). It stores a two-byte length header at the start of the buffer and copies the payload from the write fifo starting at buf + KLSI_HDR_LEN, but passes the full buffer size as the number of bytes to copy: count = kfifo_out_locked(&port->write_fifo, buf + KLSI_HDR_LEN, size, &port->lock); When the fifo holds at least size bytes, size bytes are copied starting two bytes into the size-byte buffer, writing KLSI_HDR_LEN bytes past its end. Copy at most size - KLSI_HDR_LEN bytes instead, leaving room for the header as safe_serial already does. Writing bulk_out_size or more bytes to the tty triggers a slab out-of-bounds write, observed with KASAN by emulating the device with dummy_hcd and raw-gadget: BUG: KASAN: slab-out-of-bounds in kfifo_copy_out+0x83/0xc0 Write of size 64 at addr ffff888112c62202 by task python3 kfifo_copy_out klsi_105_prepare_write_buffer [kl5kusb105] usb_serial_generic_write_start [usbserial] Allocated by task 139: usb_serial_probe [usbserial] The buggy address is located 2 bytes inside of allocated 64-byte region The out-of-bounds write no longer occurs with this change applied.
Quoted source text, attributed separately from HOL analysis.
CVSS is 7.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=60b3013cdaf3fa8a17243ca46b19db3cbe08d943 <60af1fd82983c26604102e63a3fcc822c186cceb || >=60b3013cdaf3fa8a17243ca46b19db3cbe08d943 <0a57320f71941d4e0b1307453c9a1f0939afe666 || >=60b3013cdaf3fa8a17243ca46b19db3cbe08d943 <14147b7963685957839c76ba8094924e22777d79 || >=60b3013cdaf3fa8a17243ca46b19db3cbe08d943 <a1288cd700f721c1a119c4f1e8efa234e59caada || >=60b3013cdaf3fa8a17243ca46b19db3cbe08d943 <70d86e355c564b5510fde61361df014f5476c83e || >=60b3013cdaf3fa8a17243ca46b19db3cbe08d943 <372f33ebed747d91870f57c0a2e62884a870bffa || >=60b3013cdaf3fa8a17243ca46b19db3cbe08d943 <bde742b076cbe26ecc89c8c68c76ae076a524d02 || >=60b3013cdaf3fa8a17243ca46b19db3cbe08d943 <96d47e40bf9db4a9efd5c8fb53287a508d165f14 | 60af1fd82983c26604102e63a3fcc822c186cceb, 0a57320f71941d4e0b1307453c9a1f0939afe666, 14147b7963685957839c76ba8094924e22777d79, a1288cd700f721c1a119c4f1e8efa234e59caada, 70d86e355c564b5510fde61361df014f5476c83e, 372f33ebed747d91870f57c0a2e62884a870bffa, bde742b076cbe26ecc89c8c68c76ae076a524d02, 96d47e40bf9db4a9efd5c8fb53287a508d165f14 |
| Linux/Linuxgeneric | 2.6.35 | Not reported |
Published upstream
Jun 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jun 25, 2026
In the Linux kernel, the following vulnerability has been resolved: USB: serial: kl5kusb105: fix bulk-out buffer overflow klsi_105_prepare_write_buffer() is called by the generic write path with the bulk-out buffer and its size (bulk_out_size, 64 bytes). It stores a two-byte length header at the start of the buffer and copies the payload from the write fifo starting at buf + KLSI_HDR_LEN, but passes the full buffer size as the number of bytes to copy: count = kfifo_out_locked(&port->write_fifo, buf + KLSI_HDR_LEN, size, &port->lock); When the fifo holds at least size bytes, size bytes are copied starting two bytes into the size-byte buffer, writing KLSI_HDR_LEN bytes past its end. Copy at most size - KLSI_HDR_LEN bytes instead, leaving room for the header as safe_serial already does. Writing bulk_out_size or more bytes to the tty triggers a slab out-of-bounds write, observed with KASAN by emulating the device with dummy_hcd and raw-gadget: BUG: KASAN: slab-out-of-bounds in kfifo_copy_out+0x83/0xc0 Write of size 64 at addr ffff888112c62202 by task python3 kfifo_copy_out klsi_105_prepare_write_buffer [kl5kusb105] usb_serial_generic_write_start [usbserial] Allocated by task 139: usb_serial_probe [usbserial] The buggy address is located 2 bytes inside of allocated 64-byte region The out-of-bounds write no longer occurs with this change applied.
Quoted source text, attributed separately from HOL analysis.