Description
In the Linux kernel, the following vulnerability has been resolved:

usb: typec: ucsi: displayport: Fix OOB altmode array index

The UCSI displayport driver indexes the connector's port altmode array
with the GET_CURRENT_CAM response after checking it is not 0xff. The
port altmode array is UCSI_MAX_ALTMODES elements long. If the PPM
returns an invalid GET_CURRENT_CAM response above UCSI_MAX_ALTMODES and
not equal to 0xff, the kernel may crash with an array index OOB error.

Update the UCSI displayport driver to verify the current cam is less
than UCSI_MAX_ALTMODES before accessing the port altmode array.
Published: 2026-09-16
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Crash due to Array Index OOB
Action: Apply Patch
AI Analysis

Impact

The Linux kernel’s UCSI displayport driver back‑ends the current camera mode (GET_CURRENT_CAM) to index a port alternate mode array that is sized to UCSI_MAX_ALTMODES. If the PPM returns a mode index larger than this size and not equal to the sentinel 0xff, the driver will read past the array bounds. This out‑of‑bounds memory access can trigger a kernel panic, resulting in a denial‑of‑service for all users on the affected machine.

Affected Systems

The vulnerability is present in all Linux kernel versions that implement the legacy UCSI displayport driver without the added bounds check. This includes any distribution kernel that contains the ucsick_displayport.c code prior to the commit that implements the verification of the current cam against UCSI_MAX_ALTMODES. Consequently, systems running older releases of the Linux kernel that expose the UCSI interface for USB‑C displayport support are susceptible.

Risk and Exploitability

The CVSS score of 7.7 classifies the issue as high severity, while the EPSS score of less than 1% indicates a low probability of real‑world exploitation. The problem is not listed in CISA’s KEV catalog. The likely attack vector requires an attacker to provide a USB‑C device capable of acting as a UCSI host and to send a crafted GET_CURRENT_CAM response. No public exploits have been disclosed at the time of writing.

Generated by OpenCVE AI on September 18, 2026 at 07:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that contains the commit correcting the array indexing bug (for example, the commit 04cec690b1fd9d1c4c314b91a10d8c68a3acfe18).
  • If an immediate kernel upgrade is not possible, temporarily disable the UCSI displayport driver or block untrusted USB‑C connections until the patch is applied.
  • Continuously monitor kernel logs for panic messages originating from ucsi_displayport.c to detect premature crashes while awaiting the fix.

Generated by OpenCVE AI on September 18, 2026 at 07:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: displayport: Fix OOB altmode array index The UCSI displayport driver indexes the connector's port altmode array with the GET_CURRENT_CAM response after checking it is not 0xff. The port altmode array is UCSI_MAX_ALTMODES elements long. If the PPM returns an invalid GET_CURRENT_CAM response above UCSI_MAX_ALTMODES and not equal to 0xff, the kernel may crash with an array index OOB error. Update the UCSI displayport driver to verify the current cam is less than UCSI_MAX_ALTMODES before accessing the port altmode array.
Title usb: typec: ucsi: displayport: Fix OOB altmode array index
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:41:40.331Z

Reserved: 2026-09-11T19:38:34.782Z

Link: CVE-2026-90025

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:15.487

Modified: 2026-09-16T15:18:25.790

Link: CVE-2026-90025

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T07:15:04Z

Weaknesses

No weakness.