Out-of-bounds write in Linux kernel - CVE-2026-89471
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local privileged user to corrupt kernel memory.
The vulnerability exists due to an out-of-bounds write in cros_usbpd_charger_probe() in the cros_usbpd-charger driver when processing EC-reported USB PD and charger port counts. A local privileged user can cause a compromised EC to report port counts exceeding the fixed ports[] array capacity to corrupt kernel memory.
The ports[] array contains eight entries.