Description
In the Linux kernel, the following vulnerability has been resolved:

power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS

Currently the cros_usbpd-charger driver probe iterates based on raw
charger port count returned by the embedded controller. The only check
is against the number of USB PD ports which the embedded controller
also defines. A malicious embedded controller could return an inaccurate
port count (up to 255) resulting in an out of bounds write and
subsequent memory corruption.

Update helper functions in cros_usbpd-charger to limit port counts to
EC_USB_PD_MAX_PORTS.
Published: 2026-09-11
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption
Action: Immediate Patch
AI Analysis

Impact

In the Linux kernel, the cros_usbpd charger driver incorrectly uses the raw port count supplied by the embedded controller to iterate over charger ports. If an attacker controls the embedded controller, they can return an inflated port count of up to bounds of its allocated memory. This out‑of‑bounds write results in kernel memory corruption (CWE‑787) and could lead to a system crash or compromise of memory integrity.

Affected Systems

Any Linux system that runs kernel versions containing the vulnerable cros_usbpd driver is affected. The products listed by the CNA are generic Linux kernel releases; the vulnerability was fixed by limiting the port count to EC_USB_PD_MAX_PORTS. Specific kernel versions affected are not disclosed in the information provided.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.4, indicating a high impact. The EPSS score is below 1%, suggesting exploitation is currently unlikely in the wild. It is not listed in the CISA KEV catalog. The likely exploit path involves a malicious or compromised embedded controller that returns a false port count. The out‑of‑bounds write in kernel space can corrupt memory and potentially allow low‑level persistence or denial of service.

Generated by OpenCVE AI on September 15, 2026 at 22:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied kernel patch that limits port counts to EC_USB_PD_MAX_PORTS, which fixes the buffer overflow and prevents memory corruption.
  • Temporarily disable the cros_usbpd driver or its configuration until the patch is applied to avoid suspicious writes in the driver during the interim.
  • Check for updates in your distribution’s security advisories and apply the latest kernel package through the package manager to ensure the fix is installed.

Generated by OpenCVE AI on September 15, 2026 at 22:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H'}

cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS Currently the cros_usbpd-charger driver probe iterates based on raw charger port count returned by the embedded controller. The only check is against the number of USB PD ports which the embedded controller also defines. A malicious embedded controller could return an inaccurate port count (up to 255) resulting in an out of bounds write and subsequent memory corruption. Update helper functions in cros_usbpd-charger to limit port counts to EC_USB_PD_MAX_PORTS.
Title power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:00:07.466Z

Reserved: 2026-09-11T19:38:34.710Z

Link: CVE-2026-89470

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:28.140

Modified: 2026-09-14T13:19:03.310

Link: CVE-2026-89470

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:43:29Z

Links: CVE-2026-89470 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T23:00:16Z

Weaknesses