speakup: keyhelp: guard letter_offsets possible out-of-range indexing
Summary
| CVE | CVE-2026-93053 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-17 17:17:58 UTC |
| Updated | 2026-09-17 17:17:58 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: speakup: keyhelp: guard letter_offsets possible out-of-range indexing help_init() builds letter_offsets[] by using the first byte of each function name as an index via `(start & 31) - 1`. If function_names are overridden from sysfs (root) with a name starting outside [a–z], the index underflows or exceeds the array, leading to OOB write. Function names can be overridden with the following commands as root: modprobe speakup_soft echo "0 _bad" > /sys/accessibility/speakup/i18n/function_names # then press Insert+2 on /dev/tty This fix checks the first letter in help_init(), and if it is not in the [a–z] range the function returns an error to the caller. Eventually this error is propagated to drivers/accessibility/speakup/main.c:2217, which causes a bleep sound. |
Risk And Classification
EPSS: 0.001760000 probability, percentile 0.074600000 (date 2026-09-18)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected c6e3fd22cd538365bfeb82997d5b89562e077d42 fd339b9ef0accb2c24a5285df842552ebf5eb146 git | Not specified |
| CNA | Linux | Linux | affected c6e3fd22cd538365bfeb82997d5b89562e077d42 900cd6e5ef46bd15153762fb26bb03f874fccc52 git | Not specified |
| CNA | Linux | Linux | affected c6e3fd22cd538365bfeb82997d5b89562e077d42 6b39969c724d39b6062efa354dc2d38442bfd021 git | Not specified |
| CNA | Linux | Linux | affected c6e3fd22cd538365bfeb82997d5b89562e077d42 2e91ab73f9beb659f581e2a6a09f79ace1140905 git | Not specified |
| CNA | Linux | Linux | affected c6e3fd22cd538365bfeb82997d5b89562e077d42 d7deb90c4cd086cb111f0ecc9da021218fbde1b0 git | Not specified |
| CNA | Linux | Linux | affected c6e3fd22cd538365bfeb82997d5b89562e077d42 5310334762c3f08f51dc2414344dd47492c07d1d git | Not specified |
| CNA | Linux | Linux | affected c6e3fd22cd538365bfeb82997d5b89562e077d42 ca4489b3e54666a7cac7294e71a3cf64e5e95286 git | Not specified |
| CNA | Linux | Linux | affected c6e3fd22cd538365bfeb82997d5b89562e077d42 6a19ad4d68c95185308cd9e5d169b10a2cf236c8 git | Not specified |
| CNA | Linux | Linux | affected 2.6.37 | Not specified |
| CNA | Linux | Linux | unaffected 2.6.37 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.270 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.221 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.188 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.157 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.110 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.52 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2.6 7.2.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.3-rc1 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/d7deb90c4cd086cb111f0ecc9da021218fbde1b0 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/6b39969c724d39b6062efa354dc2d38442bfd021 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/fd339b9ef0accb2c24a5285df842552ebf5eb146 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/2e91ab73f9beb659f581e2a6a09f79ace1140905 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/5310334762c3f08f51dc2414344dd47492c07d1d | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/ca4489b3e54666a7cac7294e71a3cf64e5e95286 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/6a19ad4d68c95185308cd9e5d169b10a2cf236c8 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/900cd6e5ef46bd15153762fb26bb03f874fccc52 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.