Description
In the Linux kernel, the following vulnerability has been resolved:

platform/chrome: cros_ec_typec: Reject out-of-bounds PD cap count

cros_typec_register_partner_pdos() copies the partner PDOs from the EC
TYPEC_STATUS response into the fixed caps_desc.pdo[PDO_MAX_OBJECTS] array.

memcpy(caps_desc.pdo, resp->source_cap_pdos,
sizeof(u32) * resp->source_cap_count);
...
memcpy(caps_desc.pdo, resp->sink_cap_pdos,
sizeof(u32) * resp->sink_cap_count);

PDO_MAX_OBJECTS is 7. source_cap_count and sink_cap_count are u8 fields
from the EC. The only check is that they are not both zero. If either is
larger than 7, the memcpy writes past the end of the array on the stack.
A count of 255 overflows it by about 1 KB. The EC source arrays are only
seven entries wide. A larger count reads past them too.

The ChromeOS EC firmware caps these counts today, so a compliant setup
does not hit this. The kernel should still validate these values rather
than trust them.

Validate the counts in cros_typec_register_partner_pdos() next to the
memcpy. Skip the PDO registration if either count is above PDO_MAX_OBJECTS.
The rest of cros_typec_handle_status() still runs so events are handled
and cleared.
Published: 2026-09-17
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Buffer overflow leading to kernel crash
Action: Immediate patch
AI Analysis

Impact

The vulnerability arises from the Cros EC Type‑C driver in the Linux kernel copying power‑delivery capability descriptors supplied by the embedded controller into a fixed array of seven entries. The driver reads the descriptor count directly from the EC and uses it in a memcpy without checking against the array size. If the EC reports more than seven descriptors, the memcpy overruns the stack buffer, corrupting adjacent kernel data and potentially causing a kernel crash.

Affected Systems

The flaw resides in the Linux kernel Cros EC Type‑C driver. Devices that load this driver—such as ChromeOS kernels or Linux derivatives that use the same embedded‑controller interface—are affected. No specific kernel version range is listed in the CVE data, so any unpatched kernel containing this driver should be considered vulnerable.

Risk and Exploitability

The CVSS score of 8.4 indicates high severity. The EPSS score of <1% suggests that exploitation is currently rare, and the vulnerability is not listed in CISA’s KEV catalog. The CVE description does not specify how an attacker might manipulate the EC’s PD capability count. It is inferred that exploiting this flaw would require tampering with the embedded controller firmware or influencing its responses, which may be possible with physical or firmware‑level access. Without a confirmed exploit path, the actual risk depends on an attacker’s ability to alter the EC behavior.

Generated by OpenCVE AI on September 20, 2026 at 01:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a release that validates PD capability counts before copying in the Cros EC Type‑C driver.
  • Verify that any embedded controller firmware applied to the device is signed, authenticated, and installed through trusted channels.
  • If USB‑PD functionality is not required, disable or block USB‑PD communication to reduce the attack surface.

Generated by OpenCVE AI on September 20, 2026 at 01:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-787

Sat, 19 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-786

Sat, 19 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-786

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: platform/chrome: cros_ec_typec: Reject out-of-bounds PD cap count cros_typec_register_partner_pdos() copies the partner PDOs from the EC TYPEC_STATUS response into the fixed caps_desc.pdo[PDO_MAX_OBJECTS] array. memcpy(caps_desc.pdo, resp->source_cap_pdos, sizeof(u32) * resp->source_cap_count); ... memcpy(caps_desc.pdo, resp->sink_cap_pdos, sizeof(u32) * resp->sink_cap_count); PDO_MAX_OBJECTS is 7. source_cap_count and sink_cap_count are u8 fields from the EC. The only check is that they are not both zero. If either is larger than 7, the memcpy writes past the end of the array on the stack. A count of 255 overflows it by about 1 KB. The EC source arrays are only seven entries wide. A larger count reads past them too. The ChromeOS EC firmware caps these counts today, so a compliant setup does not hit this. The kernel should still validate these values rather than trust them. Validate the counts in cros_typec_register_partner_pdos() next to the memcpy. Skip the PDO registration if either count is above PDO_MAX_OBJECTS. The rest of cros_typec_handle_status() still runs so events are handled and cleared.
Title platform/chrome: cros_ec_typec: Reject out-of-bounds PD cap count
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:56:27.561Z

Reserved: 2026-09-17T16:02:15.092Z

Link: CVE-2026-93190

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:15.177

Modified: 2026-09-18T18:18:24.450

Link: CVE-2026-93190

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:45:16Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-787

    Out-of-bounds Write