Improper Validation of Specified Quantity in Input in Linux kernel - CVE-2026-93085

 

Improper Validation of Specified Quantity in Input in Linux kernel - CVE-2026-93085

Published: September 18, 2026


Vulnerability identifier: #VU150926
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-93085
CWE-ID: CWE-1284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause SCMI protocol ID truncation or aliasing.

The vulnerability exists due to improper validation of specified quantities in input in the SCMI device tree parsing paths when processing a malformed 32-bit device tree reg value. A local user can provide an out-of-range protocol ID to cause SCMI protocol ID truncation or aliasing.


Affected software

Linux kernel

How to mitigate CVE-2026-93085

Install security update from vendor's repository.


External References

Related Security Bulletins