CVE-2026-53386: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: iio: adc: ti-ads1298: add bounds check to pga_settings index ads1298_pga_settings has 7 elements but ADS1298_MASK_CH_PGA can yield values 0-7. If it yields a value >= 7, this causes an out-of-bounds array access. Add a bounds check and return -EINVAL if the index is out of range. Note that the remaining value b111 is reserved so should not be seen in a correctly functioning system.

Affected products

  • Linux Linux Kernel: from 6.9, before 6.12.95 (fixed in 6.12.95); from 6.13, before 6.18.37 (fixed in 6.18.37); from 6.19, before 7.0.14 (fixed in 7.0.14); from 7.1, before 7.1.2 (fixed in 7.1.2)

Published 2026-07-19. Last modified 2026-08-17.