CVE-2026-53045
A bug in the Linux kernel’s memory timing logic for Nvidia Tegra124 devices has been fixed. The code that determines whether a DLL is enabled was reversed, potentially allowing an attacker to manipulate memory timings. The issue is now resolved in updated kernel releases.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel users running the tegra124-emc memory controller, such as systems with Nvidia Tegra124 hardware. Any distribution that ships the affected kernel version is impacted.
Real-world impact
An attacker could exploit the incorrect DLL enable check to alter memory timings, leading to arbitrary code execution or privilege escalation on the affected system.
Why this severity
The CVSS score of 9.8 reflects that the flaw can be triggered over the network without authentication, gives the attacker full control over the system, and has no mitigations in place. The vulnerability allows complete compromise, hence the critical rating.
What to do about it
- 01Upgrade the Linux kernel to a version that includes the fix for CVE-2026-53045.
- 02Reboot the system to load the updated kernel.
NVD-referenced vendor advisory
Timeline
- Jun 24, 2026 · Jun 24, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 21, 2026 · 13d agoAdvisory updatedThe NVD record was last revised.
- Jul 21, 2026 · 13d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- git.kernel.org/stable/c/05f138fc7e27ee8e7a…patch
- git.kernel.org/stable/c/1793249c067a4b28e1…patch
- git.kernel.org/stable/c/1ebbbef47d11cc9021…patch
- git.kernel.org/stable/c/2369b1831161356e1b…patch
- git.kernel.org/stable/c/7e19e72f306484996c…patch
- git.kernel.org/stable/c/9597ab9a8296ab337e…patch
- git.kernel.org/stable/c/a85967331144fde930…patch
- git.kernel.org/stable/c/db0ae80865b515cc0b…patch