PT-2026-93666 · Linux · Linux Kernel
CVE-2026-90025
·
Published
2026-09-16
·
Updated
2026-09-24
CVSS v3.1
7.7
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The UCSI displayport driver contains an out-of-bounds (OOB) array index issue. The driver uses the response from a GET CURRENT CAM request to index the connector's port altmode array. While it checks that the response is not 0xff, it fails to verify if the value is within the bounds of the
UCSI MAX ALTMODES array length. If a Port Manager (PPM) returns a value greater than UCSI MAX ALTMODES and not equal to 0xff, it can lead to a kernel crash.Recommendations
Update the UCSI displayport driver to ensure the current cam value is verified as less than
UCSI MAX ALTMODES before accessing the port altmode array.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel