PT-2026-94859 · Linux · Linux Kernel
CVE-2026-93061
·
Published
2026-09-17
·
Updated
2026-09-28
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A stack over-read exists in the debug output helpers of the host1x GPU driver. The functions
host1x debug output() and host1x debug cont() utilize vsnprintf(), which returns the total length the formatted string would have reached if the buffer were unbounded. This return value is then passed to o->fn as the number of bytes to emit. If a call to host1x debug * produces a string exceeding 256 bytes, it can lead to a read past the end of the output buffer. This issue specifically affects debugfs files, as the printk debug sink does not use the byte count.Recommendations
Update the Linux kernel to a version where
vsnprintf() has been replaced by vscnprintf() in the host1x debug output helpers to ensure the number of bytes actually written is returned.Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel