« Volver al listado

CVE-2026-93119

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

usb: ljca: bound bank_num in ljca_enumerate_gpio()

ljca_enumerate_gpio() reads desc->bank_num from the device and loops valid_pin[i] = get_unaligned_le32(...) for i < bank_num. valid_pin[] holds only LJCA_MAX_GPIO_NUM / 32 = 2 entries.

Two checks run before the loop. The reply length must match struct_size(desc, bank_desc, bank_num). The product pins_per_bank * bank_num must not exceed LJCA_MAX_GPIO_NUM. Neither one bounds bank_num against the size of valid_pin[].

Leer descripción completaMostrar menos

The reply is capped at LJCA_MAX_PAYLOAD_SIZE (60) bytes, so the struct_size check limits bank_num to 9. A device that reports bank_num 9 with pins_per_bank 7 still passes both checks. gpio_num is 63 and the reply is 56 bytes. The loop then writes nine u32 into the two entry array and overruns valid_pin[] on the stack.

A broken or malicious LJCA device can therefore overflow the stack. Reject a bank_num that does not fit valid_pin[].

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-93119",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "acd6199f195d6de814ac4090ce0864a613b1580e",
              "lessThan": "0069593170a3d177de793c9a0b36989c4f069111",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "acd6199f195d6de814ac4090ce0864a613b1580e",
              "lessThan": "aed958c4f784a29cf42abb3e54af51a16bddde46",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "acd6199f195d6de814ac4090ce0864a613b1580e",
              "lessThan": "9c4bc8f7426aa001387800bf0140bfc5087a6de3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "acd6199f195d6de814ac4090ce0864a613b1580e",
              "lessThan": "dd9483726d0f16c1a56879c3edb65128259a4e2b",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/usb/misc/usb-ljca.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.7"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.7",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/usb/misc/usb-ljca.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:18:06.553",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0069593170a3d177de793c9a0b36989c4f069111",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9c4bc8f7426aa001387800bf0140bfc5087a6de3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/aed958c4f784a29cf42abb3e54af51a16bddde46",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/dd9483726d0f16c1a56879c3edb65128259a4e2b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: ljca: bound bank_num in ljca_enumerate_gpio()\n\nljca_enumerate_gpio() reads desc->bank_num from the device and loops\nvalid_pin[i] = get_unaligned_le32(...) for i < bank_num. valid_pin[]\nholds only LJCA_MAX_GPIO_NUM / 32 = 2 entries.\n\nTwo checks run before the loop. The reply length must match\nstruct_size(desc, bank_desc, bank_num). The product\npins_per_bank * bank_num must not exceed LJCA_MAX_GPIO_NUM. Neither one\nbounds bank_num against the size of valid_pin[]. The reply is capped at\nLJCA_MAX_PAYLOAD_SIZE (60) bytes, so the struct_size check limits\nbank_num to 9. A device that reports bank_num 9 with pins_per_bank 7\nstill passes both checks. gpio_num is 63 and the reply is 56 bytes. The\nloop then writes nine u32 into the two entry array and overruns\nvalid_pin[] on the stack.\n\nA broken or malicious LJCA device can therefore overflow the stack.\nReject a bank_num that does not fit valid_pin[]."
    }
  ],
  "lastModified": "2026-09-17T17:18:06.553",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}