Out-of-bounds read in Linux kernel - CVE-2026-93272
Published: September 25, 2026
Vulnerability details
The vulnerability allows a local user to cause regulator initialization failures.
The vulnerability exists due to out-of-bounds access in the qcom_wcnss regulator initialization routine when initializing regulators after attaching power domains. A local user can trigger remoteproc regulator initialization to cause regulator initialization failures.
The issue affects pronto-v3 platforms that do not list power-domain regulators in the vregs array.