Description
In the Linux kernel, the following vulnerability has been resolved:

gpu: host1x: Avoid stack over-read in debug output helpers

host1x_debug_output() and host1x_debug_cont() used vsnprintf(), which
returns the length the formatted string would have reached with an
unbounded buffer. That return value was passed straight to o->fn as
the number of bytes to emit.

This could cause a read past end of the output buffer if a call to
host1x_debug_* produced a string longer than 256 bytes. This only
affected the debugfs files as the printk debug sink ignores the
number of bytes. In practice, this is very unlikely to occur.

Fix by switching to vscnprintf(), which returns the number of bytes
actually written.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Assess Impact
AI Analysis

Impact

The flaw involves a stack over-read in the Linux kernel debug output helpers for the host1x GPU driver. When host1x_debug_output() or host1x_debug_cont() produce a string longer than 256 bytes, the length reported by vsnprintf() is incorrectly forwarded to the output sink, potentially causing a read that exceeds the bounds of the output buffer. A malicious actor could exploit this to read uncontrolled data from kernel memory, leading to information disclosure. The weakness is a classic buffer over-read, as recognized by CWE-179.

Affected Systems

Linux kernel implementations using the host1x GPU driver are affected. The vulnerability description does not specify particular kernel versions, so any release with this implementation before the applied fix is vulnerable.

Risk and Exploitability

The EPSS score of less than 1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KeV catalog. Exploitation would require local privileged access to the system’s debugfs interface, which is normally restricted. The vulnerability would not allow remote code execution or denial of service, but could expose sensitive kernel data to a privileged attacker. Given the low exploitation likelihood, monitoring for unusual debugfs activity and applying the kernel patch when available are recommended.

Generated by OpenCVE AI on September 19, 2026 at 12:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a Linux kernel update that replaces vsnprintf() with vscnprintf() in host1x_debug_output() and host1x_debug_cont() to prevent the buffer over-read.
  • If an update is not immediately available, restrict or disable access to the host1x debugfs files for non‑privileged users.
  • If the update is pending, unload or blacklist the host1x driver module to prevent exposure until the patch is applied.

Generated by OpenCVE AI on September 19, 2026 at 12:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-179

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: gpu: host1x: Avoid stack over-read in debug output helpers host1x_debug_output() and host1x_debug_cont() used vsnprintf(), which returns the length the formatted string would have reached with an unbounded buffer. That return value was passed straight to o->fn as the number of bytes to emit. This could cause a read past end of the output buffer if a call to host1x_debug_* produced a string longer than 256 bytes. This only affected the debugfs files as the printk debug sink ignores the number of bytes. In practice, this is very unlikely to occur. Fix by switching to vscnprintf(), which returns the number of bytes actually written.
Title gpu: host1x: Avoid stack over-read in debug output helpers
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:47.786Z

Reserved: 2026-09-17T15:57:05.660Z

Link: CVE-2026-93061

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:59.767

Modified: 2026-09-17T17:17:59.767

Link: CVE-2026-93061

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T14:00:14Z

Weaknesses
  • CWE-179

    Incorrect Behavior Order: Early Validation