Out-of-bounds write in Linux kernel - CVE-2026-89470

 

Out-of-bounds write in Linux kernel - CVE-2026-89470

Published: September 12, 2026


Vulnerability identifier: #VU149335
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-89470
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker with physical access to cause memory corruption.

The vulnerability exists due to an out-of-bounds write in the cros_usbpd-charger driver probe when processing a raw charger port count returned by the embedded controller. An attacker with physical access can cause the embedded controller to report an inaccurate port count to cause memory corruption.

The embedded controller can report a port count of up to 255.


Affected software

Linux kernel

How to mitigate CVE-2026-89470

Install security update from vendor's repository.


External References

Related Security Bulletins