SB2026091838 - Out-of-bounds read in Linux kernel platform chrome driver
Published: September 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-93165)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to overread memory.
The vulnerability exists due to an out-of-bounds read in cros_ec_sensorhub_ring_handler() when processing FIFO information responses from EC firmware. A local privileged user can cause the handler to process a response whose length is shorter than expected to overread memory.
The condition can occur when EC firmware reports inconsistent maximum response and sensor-count values.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/6268f46d83875d294d75b68b97a5b79953744598
- https://git.kernel.org/stable/c/7780d93ae28f31fe517417c9451255315d1ad584
- https://git.kernel.org/stable/c/7e901aaf95828364b05a2120a1bea1a1669bdc9a
- https://git.kernel.org/stable/c/847a5ba0ac75f609e3f88da905251f7a76179145
- https://git.kernel.org/stable/c/86bcfab7dff6f0a61cbe0660e5176e907353141b
- https://git.kernel.org/stable/c/98604cc8fd2578442f49cd113481e8fc83bc0ad3
- https://git.kernel.org/stable/c/d1ceb2b2324717fa30b44d56ef0c52813e239569
- https://git.kernel.org/stable/c/ee0403520cdbcf87e853df9aaa9b518a0684ed38