Stack-based buffer overflow in Linux kernel - CVE-2026-93190
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local privileged user to cause memory corruption.
The vulnerability exists due to a stack-based buffer overflow in cros_typec_register_partner_pdos() when processing EC TYPEC_STATUS responses with a source or sink PDO count exceeding PDO_MAX_OBJECTS. A local privileged user can provide a response with an oversized PDO count to cause memory corruption.
Affected software
How to mitigate CVE-2026-93190
External References
- https://git.kernel.org/stable/c/2a7a4e45a3aa4f4ef7013eb64649f6184b76a293
- https://git.kernel.org/stable/c/4e37371cb4e3b8ff564d7760029236a7bd614562
- https://git.kernel.org/stable/c/54d6b0ee9b8ba434089b11843effc111dc2e6ead
- https://git.kernel.org/stable/c/7617b210a2200b76d8f171819390468c7d189c80
- https://git.kernel.org/stable/c/a0a8cd9fc9c48b95095bcec4b146f7a99486f58e
- https://git.kernel.org/stable/c/e4728288473a5024a8bdba7d43f346719606fea0