SB20260912313 - Out-of-bounds write in Linux kernel power supply driver



SB20260912313 - Out-of-bounds write in Linux kernel power supply driver

Published: September 12, 2026

Security Bulletin ID SB20260912313
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Physical access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Out-of-bounds write (CVE-ID: CVE-2026-89470)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to cause memory corruption.

The vulnerability exists due to an out-of-bounds write in the cros_usbpd-charger driver probe when processing a raw charger port count returned by the embedded controller. An attacker with physical access can cause the embedded controller to report an inaccurate port count to cause memory corruption.

The embedded controller can report a port count of up to 255.


Remediation

Install update from vendor's website.