CVE-2026-53295
mailbox: add sanity check for channel array
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
26 Jun 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In the Linux kernel, the following vulnerability has been resolved:
mailbox: add sanity check for channel array
Fail gracefully if there is no channel array attached to the mailbox
controller. Otherwise the later dereference will cause an OOPS which
might not be seen because mailbox controllers might instantiate very
early. Remove the comment explaining the obvious while here.
Affected products
Linux · LinuxWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://git.kernel.org/stable/c/0f11444271110d9b5bc6316a153c6431abda899chttps://git.kernel.org/stable/c/14aed0d4e58389cc6a88acf8610b12d3e476272bhttps://git.kernel.org/stable/c/37792091ab28ba030fd8d61184c47d4d51294170https://git.kernel.org/stable/c/5cc3300fab262b26c28bc2fc06df693410c3840bhttps://git.kernel.org/stable/c/6362c4a7d7e21e68cd9aa04df7cde16befba3a4bhttps://git.kernel.org/stable/c/9dd7489943324298bb0f385495795a82f1dd6507https://git.kernel.org/stable/c/c1aad75595fb67edc7fda8af249d3b886efa1be9https://git.kernel.org/stable/c/d44872a569b8fbacde457ff2587a775e5004bb79