« Volver al listado

CVE-2026-93190

Estado: RecibidaAlta (8.4)—

In the Linux kernel, the following vulnerability has been resolved:

platform/chrome: cros_ec_typec: Reject out-of-bounds PD cap count

cros_typec_register_partner_pdos() copies the partner PDOs from the EC TYPEC_STATUS response into the fixed caps_desc.pdo[PDO_MAX_OBJECTS] array.

PDO_MAX_OBJECTS is 7. source_cap_count and sink_cap_count are u8 fields from the EC. The only check is that they are not both zero. If either is larger than 7, the memcpy writes past the end of the array on the stack. A count of 255 overflows it by about 1 KB. The EC source arrays are only seven entries wide. A larger count reads past them too.

Leer descripción completaMostrar menos

The ChromeOS EC firmware caps these counts today, so a compliant setup does not hit this. The kernel should still validate these values rather than trust them.

Validate the counts in cros_typec_register_partner_pdos() next to the memcpy. Skip the PDO registration if either count is above PDO_MAX_OBJECTS. The rest of cros_typec_handle_status() still runs so events are handled and cleared.

Detalles técnicos trazas, registros y código del informe original
	memcpy(caps_desc.pdo, resp->source_cap_pdos,
	       sizeof(u32) * resp->source_cap_count);
	...
	memcpy(caps_desc.pdo, resp->sink_cap_pdos,
	       sizeof(u32) * resp->sink_cap_count);

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad de desbordamiento de búfer en kernel local (AV:L, PR:N) sin autenticación. Desbordamiento de ~1KB en pila permite DoS o corrupción de memoria. ChromeOS EC debe validar counts antes de memcpy.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-93190",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.4,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.5
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "348a2e8c93d3ca622cf1b293cd2f597c9db74d9d",
              "lessThan": "7617b210a2200b76d8f171819390468c7d189c80",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "348a2e8c93d3ca622cf1b293cd2f597c9db74d9d",
              "lessThan": "4e37371cb4e3b8ff564d7760029236a7bd614562",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "348a2e8c93d3ca622cf1b293cd2f597c9db74d9d",
              "lessThan": "2a7a4e45a3aa4f4ef7013eb64649f6184b76a293",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "348a2e8c93d3ca622cf1b293cd2f597c9db74d9d",
              "lessThan": "e4728288473a5024a8bdba7d43f346719606fea0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "348a2e8c93d3ca622cf1b293cd2f597c9db74d9d",
              "lessThan": "54d6b0ee9b8ba434089b11843effc111dc2e6ead",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "348a2e8c93d3ca622cf1b293cd2f597c9db74d9d",
              "lessThan": "a0a8cd9fc9c48b95095bcec4b146f7a99486f58e",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/platform/chrome/cros_ec_typec.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.1"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.1",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/platform/chrome/cros_ec_typec.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:18:15.177",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/2a7a4e45a3aa4f4ef7013eb64649f6184b76a293",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4e37371cb4e3b8ff564d7760029236a7bd614562",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/54d6b0ee9b8ba434089b11843effc111dc2e6ead",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7617b210a2200b76d8f171819390468c7d189c80",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a0a8cd9fc9c48b95095bcec4b146f7a99486f58e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e4728288473a5024a8bdba7d43f346719606fea0",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/chrome: cros_ec_typec: Reject out-of-bounds PD cap count\n\ncros_typec_register_partner_pdos() copies the partner PDOs from the EC\nTYPEC_STATUS response into the fixed caps_desc.pdo[PDO_MAX_OBJECTS] array.\n\n\tmemcpy(caps_desc.pdo, resp->source_cap_pdos,\n\t       sizeof(u32) * resp->source_cap_count);\n\t...\n\tmemcpy(caps_desc.pdo, resp->sink_cap_pdos,\n\t       sizeof(u32) * resp->sink_cap_count);\n\nPDO_MAX_OBJECTS is 7. source_cap_count and sink_cap_count are u8 fields\nfrom the EC. The only check is that they are not both zero. If either is\nlarger than 7, the memcpy writes past the end of the array on the stack.\nA count of 255 overflows it by about 1 KB. The EC source arrays are only\nseven entries wide. A larger count reads past them too.\n\nThe ChromeOS EC firmware caps these counts today, so a compliant setup\ndoes not hit this. The kernel should still validate these values rather\nthan trust them.\n\nValidate the counts in cros_typec_register_partner_pdos() next to the\nmemcpy. Skip the PDO registration if either count is above PDO_MAX_OBJECTS.\nThe rest of cros_typec_handle_status() still runs so events are handled\nand cleared."
    }
  ],
  "lastModified": "2026-09-18T18:18:24.450",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}