Description
In the Linux kernel, the following vulnerability has been resolved:

usb: ljca: bound bank_num in ljca_enumerate_gpio()

ljca_enumerate_gpio() reads desc->bank_num from the device and loops
valid_pin[i] = get_unaligned_le32(...) for i < bank_num. valid_pin[]
holds only LJCA_MAX_GPIO_NUM / 32 = 2 entries.

Two checks run before the loop. The reply length must match
struct_size(desc, bank_desc, bank_num). The product
pins_per_bank * bank_num must not exceed LJCA_MAX_GPIO_NUM. Neither one
bounds bank_num against the size of valid_pin[]. The reply is capped at
LJCA_MAX_PAYLOAD_SIZE (60) bytes, so the struct_size check limits
bank_num to 9. A device that reports bank_num 9 with pins_per_bank 7
still passes both checks. gpio_num is 63 and the reply is 56 bytes. The
loop then writes nine u32 into the two entry array and overruns
valid_pin[] on the stack.

A broken or malicious LJCA device can therefore overflow the stack.
Reject a bank_num that does not fit valid_pin[].
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: stack buffer overflow in the Linux USB ljca driver
Action: patch
AI Analysis

Impact

The flaw lies in the ljca_enumerate_gpio() function of the Linux kernel USB driver. The function reads a bank_num value supplied by an attached USB device and uses it to write into a two‑element array called valid_pin[]. The code checks that the reply length matches the expected struct size and that pins_per_bank multiplied by bank_num does not exceed the maximum number of GPIO pins, but it does not verify that bank_num fits into the two‑element array. When an attacker supplies a bank_num of nine, the loop writes nine 32‑bit words into the array, overflowing the stack and corrupting control data. This buffer overflow is a classic stack corruption that could lead to arbitrary code execution or system crash, compromising confidentiality, integrity, or availability. The vulnerability corresponds to CWE‑121.

Affected Systems

The defect exists in the Linux kernel for all vendor builds that include the ljca USB driver. Any operating system running an affected kernel version is a potential target. The issue is not limited to a specific distribution but applies to any Linux kernel that has not yet been patched for this change. Custom or older kernel builds are also at risk. The vulnerability requires physical access to the USB port; remote exploitation over the network is not possible.

Risk and Exploitability

The EPSS score is reported as less than 1%, indicating a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the lack of bounds checking allows a malicious device to overflow the stack, which could lead to arbitrary code execution if an attacker can physically attach a forged LJCA device. The absence of a publicly published CVSS score means operators cannot rely on a numeric severity gauge, but the potential for serious compromise makes the risk high if an attacker controls the USB device.

Generated by OpenCVE AI on September 19, 2026 at 07:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest Linux kernel version that includes the ljca_enumerate_gpio() bounds‑check fix.
  • Disable the ljca USB driver or block untrusted USB devices to protect the host until a patch is applied.
  • Apply kernel hardening measures, such as enabling stack protector, UEFI Secure Boot, and restricting USB access to trusted devices.

Generated by OpenCVE AI on September 19, 2026 at 07:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-121

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: usb: ljca: bound bank_num in ljca_enumerate_gpio() ljca_enumerate_gpio() reads desc->bank_num from the device and loops valid_pin[i] = get_unaligned_le32(...) for i < bank_num. valid_pin[] holds only LJCA_MAX_GPIO_NUM / 32 = 2 entries. Two checks run before the loop. The reply length must match struct_size(desc, bank_desc, bank_num). The product pins_per_bank * bank_num must not exceed LJCA_MAX_GPIO_NUM. Neither one bounds bank_num against the size of valid_pin[]. The reply is capped at LJCA_MAX_PAYLOAD_SIZE (60) bytes, so the struct_size check limits bank_num to 9. A device that reports bank_num 9 with pins_per_bank 7 still passes both checks. gpio_num is 63 and the reply is 56 bytes. The loop then writes nine u32 into the two entry array and overruns valid_pin[] on the stack. A broken or malicious LJCA device can therefore overflow the stack. Reject a bank_num that does not fit valid_pin[].
Title usb: ljca: bound bank_num in ljca_enumerate_gpio()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:25.867Z

Reserved: 2026-09-17T16:02:15.086Z

Link: CVE-2026-93119

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:06.553

Modified: 2026-09-17T17:18:06.553

Link: CVE-2026-93119

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T15:45:16Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow