Description
In the Linux kernel, the following vulnerability has been resolved:

speakup: keyhelp: guard letter_offsets possible out-of-range indexing

help_init() builds letter_offsets[] by using the first byte of each
function name as an index via `(start & 31) - 1`. If function_names are
overridden from sysfs (root) with a name starting outside [a–z], the
index underflows or exceeds the array, leading to OOB write.

Function names can be overridden with the following commands as root:

modprobe speakup_soft
echo "0 _bad" > /sys/accessibility/speakup/i18n/function_names
# then press Insert+2 on /dev/tty

This fix checks the first letter in help_init(), and if it is not in the
[a–z] range the function returns an error to the caller. Eventually this
error is propagated to drivers/accessibility/speakup/main.c:2217, which
causes a bleep sound.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Potential kernel memory corruption
Action: Apply Patch
AI Analysis

Impact

The vulnerability in the Linux kernel's speakup accessibility module allows an out‑of‑bounds write to the letter_offsets array during help_init() when a function name is overridden via sysfs with a first character outside the a–z range. The flaw can corrupt kernel memory, leading to a denial of service or other unintended kernel behavior. The impact is limited to kernel execution context and can manifest as a fatal error or a bleep sound when the exploit triggers.

Affected Systems

Linux kernel systems where the speakup module is enabled. Any kernel that includes the vulnerable speakup implementation is affected; no specific version range is listed in the advisory.

Risk and Exploitability

The EPSS score is below 1%, indicating a low probability of exploitation at this time, and the vulnerability is not listed in CISA's KEV catalog. The fix requires root write access to /sys/accessibility/speakup/i18n/function_names, so the likely attack vector is a local privilege escalation or an attacker already running as root. Despite the low exploitation probability, the kernel memory corruption could allow an attacker to compromise the system if exercised.

Generated by OpenCVE AI on September 19, 2026 at 06:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the speakup keyhelp patch or apply the patch directly.
  • If a kernel update is not immediately possible, disable the speakup module so that the sysfs interface is unavailable and the exploit path is closed.
  • Restrict write permissions on /sys/accessibility/speakup/i18n/function_names to root only, preventing unprivileged users from editing function names.

Generated by OpenCVE AI on September 19, 2026 at 06:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: speakup: keyhelp: guard letter_offsets possible out-of-range indexing help_init() builds letter_offsets[] by using the first byte of each function name as an index via `(start & 31) - 1`. If function_names are overridden from sysfs (root) with a name starting outside [a–z], the index underflows or exceeds the array, leading to OOB write. Function names can be overridden with the following commands as root: modprobe speakup_soft echo "0 _bad" > /sys/accessibility/speakup/i18n/function_names # then press Insert+2 on /dev/tty This fix checks the first letter in help_init(), and if it is not in the [a–z] range the function returns an error to the caller. Eventually this error is propagated to drivers/accessibility/speakup/main.c:2217, which causes a bleep sound.
Title speakup: keyhelp: guard letter_offsets possible out-of-range indexing
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:42.397Z

Reserved: 2026-09-17T15:57:05.658Z

Link: CVE-2026-93053

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:58.783

Modified: 2026-09-17T17:17:58.783

Link: CVE-2026-93053

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T14:15:17Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer