PT-2026-94986 · Linux · Linux Kernel
CVE-2026-93190
·
Published
2026-09-17
·
Updated
2026-09-24
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the
cros typec register partner pdos() function where partner Power Delivery Objects (PDOs) are copied from the EC TYPEC STATUS response into a fixed-size array caps desc.pdo[PDO MAX OBJECTS]. Because the source cap count and sink cap count variables are not properly validated against the PDO MAX OBJECTS limit of 7, a value larger than 7 can lead to a stack-based buffer overflow during the memcpy() operation. For instance, a count of 255 could result in an overflow of approximately 1 KB. This occurs because the kernel trusts the count values provided by the EC without sufficient validation.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel