{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-53044","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-06-09T07:44:35.381Z","datePublished":"2026-06-24T16:29:51.013Z","dateUpdated":"2026-08-05T12:32:51.816Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:32:51.816Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsoc/tegra: cbb: Fix incorrect ARRAY_SIZE in fabric lookup tables\n\nFix incorrect ARRAY_SIZE usage in fabric lookup tables which could\ncause out-of-bounds access during target timeout lookup."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The vulnerable Tegra CBB timeout decoding runs on local SoC fabric error handling paths, reached through local device/accelerator activity or local debugfs inspection of pending CBB status rather than network packets.\nAC:L - Once a timeout error with the affected fabric and target ID is generated, the bad bounds check deterministically permits the out-of-bounds lookup; there is no race or probabilistic exploitation step.\nPR:L - In the most severe reasonable Tegra deployment, an unprivileged local user can interact with device/accelerator interfaces capable of causing fabric transactions and CBB error reporting. Real init-namespace root is not inherently required by the vulnerable decode path.\nUI:N - No victim user action is required after the attacker triggers the local fabric error condition; the interrupt handler processes the error automatically.\nS:U - The impact remains within the same kernel/SoC security authority and does not cross a VM, IOMMU, or sandbox boundary.\nC:H - The incorrect ARRAY_SIZE permits out-of-bounds reads from kernel lookup data and pointer dereferences during error printing. Under the required conservative rule for out-of-bounds reads, this is scored as high confidentiality impact.\nI:N - The vulnerable path reads lookup entries and MMIO timeout status but does not provide an out-of-bounds write or a clear primitive for modifying kernel data.\nA:H - The out-of-bounds lookup can dereference invalid data or perform bogus MMIO reads while handling the CBB error, plausibly causing a kernel oops or panic."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/soc/tegra/cbb/tegra234-cbb.c"],"versions":[{"version":"25de5c8fe0801361182b41c42f086bd089feda14","lessThan":"f46870b451f7583802ed26eec8b93e138840fcd9","status":"affected","versionType":"git"},{"version":"25de5c8fe0801361182b41c42f086bd089feda14","lessThan":"5c009a5f8bb3c81f2cfb511701ce571e3c8733cd","status":"affected","versionType":"git"},{"version":"25de5c8fe0801361182b41c42f086bd089feda14","lessThan":"499f7e5ebbdd9ff0c4d532b1c432f8a61ff585b3","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/soc/tegra/cbb/tegra234-cbb.c"],"versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","status":"unaffected","versionType":"semver"},{"version":"6.18.33","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.0.10","lessThanOrEqual":"7.0.*","status":"unaffected","versionType":"semver"},{"version":"7.1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.17","versionEndExcluding":"6.18.33"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.17","versionEndExcluding":"7.0.10"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.17","versionEndExcluding":"7.1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/f46870b451f7583802ed26eec8b93e138840fcd9"},{"url":"https://git.kernel.org/stable/c/5c009a5f8bb3c81f2cfb511701ce571e3c8733cd"},{"url":"https://git.kernel.org/stable/c/499f7e5ebbdd9ff0c4d532b1c432f8a61ff585b3"}],"title":"soc/tegra: cbb: Fix incorrect ARRAY_SIZE in fabric lookup tables","x_generator":{"engine":"bippy-1.2.0"}}}}