Description
In the Linux kernel, the following vulnerability has been resolved:

platform/chrome: sensorhub: Bound the EC-reported sensor number

Each EC FIFO event carries an 8-bit sensor number (in->sensor_num).
cros_ec_sensorhub_ring_handler() validates the FIFO event count, the
per-read count and the ring bound, but not the sensor number, which
cros_ec_sensor_ring_process_event() then uses unchecked to index
sensorhub->batch_state[] - allocated with only sensorhub->sensor_num
entries. A sensor number of sensor_num or larger is an out-of-bounds
read and write of batch_state[].

Validate the sensor number in the ring handler, where each event is read
from the EC, and drop a malformed event before it is used.
Published: 2026-09-11
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption
Action: Apply Patch
AI Analysis

Impact

The kernel’s sensorhub driver processes events from the embedded controller, each event containing an 8‑bit sensor number. The handler validates FIFO event counts and ring bounds but fails to verify the sensor number before using it as an index into the batch_state array. An attacker that can supply a sensor number equal to or larger than the declared count can trigger an out‑of‑bounds read or write on batch_state, corrupting kernel memory and potentially destabilizing the system.

Affected Systems

Linux kernel builds that include the platform/chrome sensorhub driver without the sensor-number validation patch are affected. No specific kernel releases are listed, so any unpatched kernel version that ships with this driver may be vulnerable.

Risk and Exploitability

The vulnerability is rated CVSS 8.4 (v3.1), and its EPSS score of less than 1 % indicates a low current exploitation probability. It is not in CISA KEV. The likely attack vector is exploitation of the EC interface; an adversary would need to influence the embedded controller to transmit malformed sensor numbers. If such control is achieved, the kernel memory corruption could lead to system instability or compromise, but the overall threat is modest without that capability.

Generated by OpenCVE AI on September 21, 2026 at 01:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a release that includes the sensor-number validation fix.
  • If a kernel update is not feasible, unload or disable the sensorhub driver to stop processing EC events.
  • Limit or audit access to the embedded controller FIFO so only trusted firmware can send events.

Generated by OpenCVE AI on September 21, 2026 at 01:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H'}

cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: platform/chrome: sensorhub: Bound the EC-reported sensor number Each EC FIFO event carries an 8-bit sensor number (in->sensor_num). cros_ec_sensorhub_ring_handler() validates the FIFO event count, the per-read count and the ring bound, but not the sensor number, which cros_ec_sensor_ring_process_event() then uses unchecked to index sensorhub->batch_state[] - allocated with only sensorhub->sensor_num entries. A sensor number of sensor_num or larger is an out-of-bounds read and write of batch_state[]. Validate the sensor number in the ring handler, where each event is read from the EC, and drop a malformed event before it is used.
Title platform/chrome: sensorhub: Bound the EC-reported sensor number
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T11:59:48.159Z

Reserved: 2026-08-26T14:34:25.813Z

Link: CVE-2026-81017

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:10.680

Modified: 2026-09-14T13:18:55.973

Link: CVE-2026-81017

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:43:05Z

Links: CVE-2026-81017 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T01:45:07Z

Weaknesses