CVE-2026-93119
In the Linux kernel, the following vulnerability has been resolved:
usb: ljca: bound bank_num in ljca_enumerate_gpio()
ljca_enumerate_gpio() reads desc->bank_num from the device and loops valid_pin[i] = get_unaligned_le32(...) for i < bank_num. valid_pin[] holds only LJCA_MAX_GPIO_NUM / 32 = 2 entries.
Two checks run before the loop. The reply length must match struct_size(desc, bank_desc, bank_num). The product pins_per_bank * bank_num must not exceed LJCA_MAX_GPIO_NUM. Neither one bounds bank_num against the size of valid_pin[].
Leer descripción completaMostrar menos
The reply is capped at LJCA_MAX_PAYLOAD_SIZE (60) bytes, so the struct_size check limits bank_num to 9. A device that reports bank_num 9 with pins_per_bank 7 still passes both checks. gpio_num is 63 and the reply is 56 bytes. The loop then writes nine u32 into the two entry array and overruns valid_pin[] on the stack.
A broken or malicious LJCA device can therefore overflow the stack. Reject a bank_num that does not fit valid_pin[].
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-93119",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "acd6199f195d6de814ac4090ce0864a613b1580e",
"lessThan": "0069593170a3d177de793c9a0b36989c4f069111",
"versionType": "git"
},
{
"status": "affected",
"version": "acd6199f195d6de814ac4090ce0864a613b1580e",
"lessThan": "aed958c4f784a29cf42abb3e54af51a16bddde46",
"versionType": "git"
},
{
"status": "affected",
"version": "acd6199f195d6de814ac4090ce0864a613b1580e",
"lessThan": "9c4bc8f7426aa001387800bf0140bfc5087a6de3",
"versionType": "git"
},
{
"status": "affected",
"version": "acd6199f195d6de814ac4090ce0864a613b1580e",
"lessThan": "dd9483726d0f16c1a56879c3edb65128259a4e2b",
"versionType": "git"
}
],
"programFiles": [
"drivers/usb/misc/usb-ljca.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.7"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.7",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.12.110",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.52",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.6",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/usb/misc/usb-ljca.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-17T17:18:06.553",
"references": [
{
"url": "https://git.kernel.org/stable/c/0069593170a3d177de793c9a0b36989c4f069111",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/9c4bc8f7426aa001387800bf0140bfc5087a6de3",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/aed958c4f784a29cf42abb3e54af51a16bddde46",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/dd9483726d0f16c1a56879c3edb65128259a4e2b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: ljca: bound bank_num in ljca_enumerate_gpio()\n\nljca_enumerate_gpio() reads desc->bank_num from the device and loops\nvalid_pin[i] = get_unaligned_le32(...) for i < bank_num. valid_pin[]\nholds only LJCA_MAX_GPIO_NUM / 32 = 2 entries.\n\nTwo checks run before the loop. The reply length must match\nstruct_size(desc, bank_desc, bank_num). The product\npins_per_bank * bank_num must not exceed LJCA_MAX_GPIO_NUM. Neither one\nbounds bank_num against the size of valid_pin[]. The reply is capped at\nLJCA_MAX_PAYLOAD_SIZE (60) bytes, so the struct_size check limits\nbank_num to 9. A device that reports bank_num 9 with pins_per_bank 7\nstill passes both checks. gpio_num is 63 and the reply is 56 bytes. The\nloop then writes nine u32 into the two entry array and overruns\nvalid_pin[] on the stack.\n\nA broken or malicious LJCA device can therefore overflow the stack.\nReject a bank_num that does not fit valid_pin[]."
}
],
"lastModified": "2026-09-17T17:18:06.553",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}