{"id":"CVE-2026-64237","summary":"Input: elan_i2c - validate firmware size before use","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: elan_i2c - validate firmware size before use\n\nEnsure that the firmware file is large enough to contain the expected\nnumber of pages and the signature (which resides at the end of the\nfirmware blob) before accessing them to prevent potential out-of-bounds\nreads.","modified":"2026-09-18T10:11:48.276083519Z","published":"2026-07-24T15:27:41.937Z","related":["SUSE-SU-2026:23477-1","SUSE-SU-2026:23481-1","SUSE-SU-2026:23528-1","SUSE-SU-2026:23529-1","SUSE-SU-2026:4120-1","SUSE-SU-2026:4254-1"],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64237.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/331d49b4e1c9efe4479bbd22922dfcdd8c64be7b"},{"type":"WEB","url":"https://git.kernel.org/stable/c/3b37190ad3ded3a15fb1dbfc4f26df520a3e59bb"},{"type":"WEB","url":"https://git.kernel.org/stable/c/47b52b98edfe34d0249e72f815215ef24311c3a3"},{"type":"WEB","url":"https://git.kernel.org/stable/c/48b0aa9c08a3ac8e0c0345b7ca581f552324e460"},{"type":"WEB","url":"https://git.kernel.org/stable/c/76b0d0baa9ae9c60e726bbe1b6ff0bec2c993634"},{"type":"WEB","url":"https://git.kernel.org/stable/c/bf769358419e00344c1b16fa034d058f563d46a1"},{"type":"WEB","url":"https://git.kernel.org/stable/c/c2c3b33b3c0bf2c9427c0926817ef5ffac50de6f"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d97baee9590edf303b3eca432e61de9320834fe1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64237.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64237"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"bb03bf3f8427a38112819061fc8688999ba02f67"},{"fixed":"47b52b98edfe34d0249e72f815215ef24311c3a3"},{"fixed":"c2c3b33b3c0bf2c9427c0926817ef5ffac50de6f"},{"fixed":"331d49b4e1c9efe4479bbd22922dfcdd8c64be7b"},{"fixed":"48b0aa9c08a3ac8e0c0345b7ca581f552324e460"},{"fixed":"3b37190ad3ded3a15fb1dbfc4f26df520a3e59bb"},{"fixed":"bf769358419e00344c1b16fa034d058f563d46a1"},{"fixed":"d97baee9590edf303b3eca432e61de9320834fe1"},{"fixed":"76b0d0baa9ae9c60e726bbe1b6ff0bec2c993634"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-64237.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0.0"},{"fixed":"5.10.259"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.210"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.176"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.143"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.93"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.35"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.0.12"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-64237.json"}}],"schema_version":"1.9.0"}