Out-of-bounds read in Linux kernel - CVE-2026-46073
Published: May 27, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in the powerz hwmon driver when handling a signal interruption during USB transfer completion. A local user can trigger a signal interruption and cause the driver to read from an unfilled transfer buffer to disclose sensitive information.