Description
In the Linux kernel, the following vulnerability has been resolved:

power: supply: cros_usbpd-charger: bound the EC-reported port count

cros_usbpd_charger_probe() reads two port counts from the EC and uses
one of them, num_charger_ports, as the loop bound when populating a
fixed-size array:

struct port_data *ports[EC_USB_PD_MAX_PORTS]; /* 8 entries */
...
for (i = 0; i < charger->num_charger_ports; i++)
charger->ports[charger->num_registered_psy++] = port;

Both num_usbpd_ports (from EC_CMD_USB_PD_PORTS) and num_charger_ports
(from EC_CMD_CHARGE_PORT_COUNT) are u8 values reported by the EC. The
only validation is a sanity check that compares the two EC-reported
values against each other:

if (num_charger_ports < num_usbpd_ports ||
num_charger_ports > num_usbpd_ports + 1)
return -EPROTO;

It never checks either count against EC_USB_PD_MAX_PORTS, the size of
the ports[] array. A malfunctioning, malicious or compromised EC that
reports num_usbpd_ports == num_charger_ports == N for any N > 8 (for
example both 255) passes this check, and the loop then writes N pointers
into the 8-entry ports[] array embedded in the devm_kzalloc()'d
charger_data, overflowing it by up to 255 - 8 = 247 entries (~1976
bytes): a slab out-of-bounds write.

Reject a port count larger than the ports[] array can hold.
Published: 2026-09-11
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption via out-of-bounds write
Action: Immediate Patch
AI Analysis

Impact

The cros_usbpd‑charger driver in the Linux kernel incorrectly trusts the embedded controller’s reported number of charger ports. The reported value is used as a loop bound for an 8‑entry array. If a malformed EC supplies a number larger than the array size, the loop writes beyond the array, corrupting kernel memory. This out‑of‑bounds write is a classic heap overflow (CWE‑787).

Affected Systems

The flaw exists in any Linux kernel build that includes the cros_usbpd‑charger driver before the patch that bounds num_charger_ports. This driver exposes EC USB‑PD port counts. Versions of the kernel prior to the commit referenced in the git logs are vulnerable, while all kernels which incorporate the new bounds check are safe.

Risk and Exploitability

Risk originates from a heap out‑of‑bounds write that can corrupt kernel memory. The CVSS score of 8.4 indicates high severity, while the EPSS score of less than 1 % suggests a very low probability of public exploitation at present. The vulnerability is not listed in CISA's KEV catalog. The most likely scenario for exploitation, based on the description, is that an attacker or a malfunctioning embedded controller provides an invalid port count that exceeds the array size, causing the driver to write beyond its bounds. However, the exact attack vector and whether an exploit is possible outside of a compromised or physically accessed EC are not explicitly documented, so these details remain uncertain.

Generated by OpenCVE AI on September 15, 2026 at 22:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that adds a check against EC_USB_PD_MAX_PORTS before using num_charger_ports as a loop bound
  • Update the system to the latest kernel version that incorporates the fix
  • If a rapid update is unavailable, consider disabling the cros_usbpd‑charger driver or restricting EC access to prevent malicious port count reports

Generated by OpenCVE AI on September 15, 2026 at 22:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: power: supply: cros_usbpd-charger: bound the EC-reported port count cros_usbpd_charger_probe() reads two port counts from the EC and uses one of them, num_charger_ports, as the loop bound when populating a fixed-size array: struct port_data *ports[EC_USB_PD_MAX_PORTS]; /* 8 entries */ ... for (i = 0; i < charger->num_charger_ports; i++) charger->ports[charger->num_registered_psy++] = port; Both num_usbpd_ports (from EC_CMD_USB_PD_PORTS) and num_charger_ports (from EC_CMD_CHARGE_PORT_COUNT) are u8 values reported by the EC. The only validation is a sanity check that compares the two EC-reported values against each other: if (num_charger_ports < num_usbpd_ports || num_charger_ports > num_usbpd_ports + 1) return -EPROTO; It never checks either count against EC_USB_PD_MAX_PORTS, the size of the ports[] array. A malfunctioning, malicious or compromised EC that reports num_usbpd_ports == num_charger_ports == N for any N > 8 (for example both 255) passes this check, and the loop then writes N pointers into the 8-entry ports[] array embedded in the devm_kzalloc()'d charger_data, overflowing it by up to 255 - 8 = 247 entries (~1976 bytes): a slab out-of-bounds write. Reject a port count larger than the ports[] array can hold.
Title power: supply: cros_usbpd-charger: bound the EC-reported port count
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:00:08.543Z

Reserved: 2026-09-11T19:38:34.710Z

Link: CVE-2026-89471

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:28.263

Modified: 2026-09-14T13:19:03.463

Link: CVE-2026-89471

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:43:29Z

Links: CVE-2026-89471 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T23:00:16Z

Weaknesses