Out-of-bounds read in Linux kernel - CVE-2026-93808

 

Out-of-bounds read in Linux kernel - CVE-2026-93808

Published: September 25, 2026


Vulnerability identifier: #VU152090
CSH Severity: Low
CVSS v4: 0 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-93808
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker with physical access to cause an out-of-bounds read.

The vulnerability exists due to improper length validation in the ALSA USB CAIAQ EP1 reply handling code when processing undersized EP1 replies. An attacker with physical access can provide a malformed EP1 reply to cause an out-of-bounds read.


Affected software

Linux kernel

How to mitigate CVE-2026-93808

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins