HID: steam: Reject short reads
Summary
| CVE | CVE-2026-90328 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-17 17:17:30 UTC |
| Updated | 2026-09-17 17:17:30 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
HID: steam: Reject short reads
Steam Controller FEATURE reports encode the size of the message in the
message itself. Previously we were trusting that the size reported matched
the size we actually read, leading to a potential issue with short reads.
Instead, we should actually verify the length of the read. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected c164d6abf3841ffacfdb757c10616f9cb1f67276 f694ea0ead544080949e409a7c6885ee1fc77a98 git |
Not specified |
| CNA |
Linux |
Linux |
affected c164d6abf3841ffacfdb757c10616f9cb1f67276 93c5cc35bcd9f62db589a21945b49691dccdd99d git |
Not specified |
| CNA |
Linux |
Linux |
affected c164d6abf3841ffacfdb757c10616f9cb1f67276 33ff7b49c38b39b1f3d27db508ac0720fb25c08a git |
Not specified |
| CNA |
Linux |
Linux |
affected 4.18 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 4.18 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.52 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2.6 7.2.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.3-rc1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/f694ea0ead544080949e409a7c6885ee1fc77a98 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/93c5cc35bcd9f62db589a21945b49691dccdd99d |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/33ff7b49c38b39b1f3d27db508ac0720fb25c08a |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.