SB2026091814 - Stack-based buffer overflow in Linux kernel platform chrome driver
Published: September 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Stack-based buffer overflow (CVE-ID: CVE-2026-93190)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to cause memory corruption.
The vulnerability exists due to a stack-based buffer overflow in cros_typec_register_partner_pdos() when processing EC TYPEC_STATUS responses with a source or sink PDO count exceeding PDO_MAX_OBJECTS. A local privileged user can provide a response with an oversized PDO count to cause memory corruption.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/2a7a4e45a3aa4f4ef7013eb64649f6184b76a293
- https://git.kernel.org/stable/c/4e37371cb4e3b8ff564d7760029236a7bd614562
- https://git.kernel.org/stable/c/54d6b0ee9b8ba434089b11843effc111dc2e6ead
- https://git.kernel.org/stable/c/7617b210a2200b76d8f171819390468c7d189c80
- https://git.kernel.org/stable/c/a0a8cd9fc9c48b95095bcec4b146f7a99486f58e
- https://git.kernel.org/stable/c/e4728288473a5024a8bdba7d43f346719606fea0