PT-2026-94961 · Linux · Linux Kernel
CVE-2026-93165
·
Published
2026-09-17
·
Updated
2026-09-24
CVSS v3.1
7.7
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A memory overread exists in the ring handler of the sensorhub component. The issue occurs because
max response and sensor num are retrieved from different Embedded Controller (EC) commands. If the EC firmware malfunctions, the msg->insize (specifically fifo info length) may be clamped in the cros ec cmd xfer() function if it exceeds max response. This results in fewer bytes being read than expected, causing a subsequent memcpy() operation in the cros ec sensorhub ring handler() function to overread the resp->fifo info buffer.Recommendations
Check the return value of
cros ec cmd xfer status() and abort the operation if the number of bytes read does not match the expected length.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel