Description
In the Linux kernel, the following vulnerability has been resolved:

HID: roccat: bound device-supplied profile index

kone_keep_values_up_to_date() and kone_profile_activated() use an
8-bit, device-supplied profile value as an index into the 5-element
kone->profiles[] array without a range check. A malicious USB device
claiming the Roccat Kone id can send a switch-profile event (or a
startup_profile read at probe) with an out-of-range value and make the
driver read out of bounds; the result is exposed via the actual_dpi
sysfs attribute.

Reject out-of-range indices in both paths.

This was found with static analysis and confirmed with the KUnit test
added in the following patch (KASAN: slab-out-of-bounds).
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure via out-of-bounds read of the actual_dpi sysfs attribute
Action: Patch Immediately
AI Analysis

Impact

A malicious USB HID device claiming the Roccat Kone identifier can supply an 8‑bit profile index that exceeds the 5‑element array maintained by the driver. The driver uses the value as an array index in two code paths without a bounds check, causing an out‑of‑bounds read. The data read is exposed through the actual_dpi sysfs attribute, allowing an attacker to learn DPI settings for the mouse and potentially other internal state. This vulnerability is an out‑of‑bounds read that can leak sensitive information.

Affected Systems

The flaw exists in the Linux kernel’s Roccat HID driver for the Kone mouse and affects all kernel releases that include the unpatched driver. No specific version range is listed, so all kernels prior to the patch are potentially impacted.

Risk and Exploitability

The EPSS score is less than 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability that it will be actively exploited. The attack requires a physical USB device that can emulate a Roccat Kone and requires the device to be connected to a Linux system. Although the exploitation can read data from a sysfs file, the overall risk is modest until a patch is applied.

Generated by OpenCVE AI on September 19, 2026 at 08:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the roccat driver bounds‑check patch
  • Restrict or disconnect external HID devices until the update is installed
  • Monitor sysfs attributes such as /sys/class/hidraw/.../actual_dpi for unexpected values

Generated by OpenCVE AI on September 19, 2026 at 08:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-20

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: HID: roccat: bound device-supplied profile index kone_keep_values_up_to_date() and kone_profile_activated() use an 8-bit, device-supplied profile value as an index into the 5-element kone->profiles[] array without a range check. A malicious USB device claiming the Roccat Kone id can send a switch-profile event (or a startup_profile read at probe) with an out-of-range value and make the driver read out of bounds; the result is exposed via the actual_dpi sysfs attribute. Reject out-of-range indices in both paths. This was found with static analysis and confirmed with the KUnit test added in the following patch (KASAN: slab-out-of-bounds).
Title HID: roccat: bound device-supplied profile index
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:12:13.482Z

Reserved: 2026-09-17T16:02:15.091Z

Link: CVE-2026-93188

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:14.887

Modified: 2026-09-17T17:18:14.887

Link: CVE-2026-93188

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:00:11Z

Weaknesses