Improper Validation of Specified Quantity in Input in Linux kernel - CVE-2026-90328
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to trigger processing of truncated Steam Controller feature reports.
The vulnerability exists due to improper validation of a declared report length in the steam_recv_report function when handling Steam Controller feature reports. A local user can provide a feature report whose declared length exceeds the number of bytes read to trigger processing of truncated feature reports.