thunderbolt: Limit XDomain response copy to actual frame size

Summary

CVECVE-2026-53146
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-06-25 09:16:31 UTC
Updated2026-06-25 09:16:31 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: thunderbolt: Limit XDomain response copy to actual frame size tb_xdomain_copy() copies req->response_size bytes from the received packet buffer regardless of the actual frame size. When a short response arrives, this reads past the valid frame data in the DMA pool buffer into stale contents from previous transactions. Use the minimum of frame size and expected response size for the copy length.

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected cdae7c07e3e3509eaabc18c1640a55dc5b99c179 c55da494dfb445fb28df3a9d293c2be6a299cd01 git Not specified
CNA Linux Linux affected cdae7c07e3e3509eaabc18c1640a55dc5b99c179 7720654b4842bcdfeb64bc002f6186041849e1e7 git Not specified
CNA Linux Linux affected cdae7c07e3e3509eaabc18c1640a55dc5b99c179 033dfa63bf6be2653441a1dccae4a8313a91bb9d git Not specified
CNA Linux Linux affected cdae7c07e3e3509eaabc18c1640a55dc5b99c179 fc261397295b8ad0654cec747b0ec25ea0011995 git Not specified
CNA Linux Linux affected cdae7c07e3e3509eaabc18c1640a55dc5b99c179 a15b6d3136accb2bf84b04d9a3ddd991f7fbf1cb git Not specified
CNA Linux Linux affected cdae7c07e3e3509eaabc18c1640a55dc5b99c179 b5daa920f44cb582272fc9bfaeb67408776cbaef git Not specified
CNA Linux Linux affected cdae7c07e3e3509eaabc18c1640a55dc5b99c179 b2c1e5d9f1598cc1a4736d5c6bd1218f90805ee4 git Not specified
CNA Linux Linux affected cdae7c07e3e3509eaabc18c1640a55dc5b99c179 4db2bd2ed4785dbadaeeab9f4e346b21ac5fb8eb git Not specified
CNA Linux Linux affected 4.15 Not specified
CNA Linux Linux unaffected 4.15 semver Not specified
CNA Linux Linux unaffected 5.10.259 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.210 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.176 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.143 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.94 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.36 6.18.* semver Not specified
CNA Linux Linux unaffected 7.0.13 7.0.* semver Not specified
CNA Linux Linux unaffected 7.1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/4db2bd2ed4785dbadaeeab9f4e346b21ac5fb8eb 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/7720654b4842bcdfeb64bc002f6186041849e1e7 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/b2c1e5d9f1598cc1a4736d5c6bd1218f90805ee4 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/fc261397295b8ad0654cec747b0ec25ea0011995 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/b5daa920f44cb582272fc9bfaeb67408776cbaef 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/c55da494dfb445fb28df3a9d293c2be6a299cd01 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/033dfa63bf6be2653441a1dccae4a8313a91bb9d 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/a15b6d3136accb2bf84b04d9a3ddd991f7fbf1cb 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report