Out-of-bounds read in Linux kernel - CVE-2026-93808
Published: September 25, 2026
Vulnerability identifier: #VU152090
CSH Severity: Low
CVSS v4: 0 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-93808
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows an attacker with physical access to cause an out-of-bounds read.
The vulnerability exists due to improper length validation in the ALSA USB CAIAQ EP1 reply handling code when processing undersized EP1 replies. An attacker with physical access can provide a malformed EP1 reply to cause an out-of-bounds read.
Affected software
Linux kernel
How to mitigate CVE-2026-93808
Install security update from vendor's repository.
Linux kernel - update to 7.0 rc3