PT-2026-94918 · Linux · Linux Kernel

CVE-2026-93122

·

Published

2026-09-17

·

Updated

2026-09-24

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An array-index-out-of-bounds issue exists in the UAC1 and UAC2 configfs rate-list attributes. The system parses a comma-separated list of sampling rates and stores them in fixed-size arrays. Because the store paths fail to validate that the input contains no more than the maximum allowed entries, providing more than ten rates allows writing past the end of the p srates[] or c srates[] arrays within the f uac1 opts or f uac2 opts structures. This occurs in the f uac1 opts p srate store() and f uac2 opts p srate store() functions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-102533
CVE-2026-93122
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel