Out-of-bounds read in Linux kernel - CVE-2026-93165
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local privileged user to overread memory.
The vulnerability exists due to an out-of-bounds read in cros_ec_sensorhub_ring_handler() when processing FIFO information responses from EC firmware. A local privileged user can cause the handler to process a response whose length is shorter than expected to overread memory.
The condition can occur when EC firmware reports inconsistent maximum response and sensor-count values.
Affected software
How to mitigate CVE-2026-93165
External References
- https://git.kernel.org/stable/c/6268f46d83875d294d75b68b97a5b79953744598
- https://git.kernel.org/stable/c/7780d93ae28f31fe517417c9451255315d1ad584
- https://git.kernel.org/stable/c/7e901aaf95828364b05a2120a1bea1a1669bdc9a
- https://git.kernel.org/stable/c/847a5ba0ac75f609e3f88da905251f7a76179145
- https://git.kernel.org/stable/c/86bcfab7dff6f0a61cbe0660e5176e907353141b
- https://git.kernel.org/stable/c/98604cc8fd2578442f49cd113481e8fc83bc0ad3
- https://git.kernel.org/stable/c/d1ceb2b2324717fa30b44d56ef0c52813e239569
- https://git.kernel.org/stable/c/ee0403520cdbcf87e853df9aaa9b518a0684ed38