What is CVE-2026-64237?
A critical vulnerability was found in the elan_i2c driver of the Linux kernel. Due to a missing firmware size validation, a specially crafted undersized file could cause memory corruption when accessing pages or the signature. Users should apply the pending kernel patch immediately.
Azərbaycanca: Bu kritik zəiflik Linux kernel-in elan_i2c sürücüsündə aşkarlanıb. Firmware faylının ölçüsü yoxlanılmadığı üçün, xüsusi hazırlanmış daha kiçik fayl səhifələrə və imzaya giriş zamanı yaddaş pozuntusuna səbəb ola bilər. İstifadəçilər kernel yeniləməsini tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-20
FAQ2
In which Linux component was CVE-2026-64237 discovered?
This vulnerability was found in the elan_i2c driver of the Linux kernel.
How can memory corruption be triggered using CVE-2026-64237?
Due to missing firmware size validation, a specially crafted undersized file could cause memory corruption when accessing pages or the signature.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.