platform/chrome: sensorhub: Fix memory overread in ring handler

Summary

CVECVE-2026-93165
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-09-17 17:18:12 UTC
Updated2026-09-17 17:18:12 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: platform/chrome: sensorhub: Fix memory overread in ring handler `max_response` and `sensor_num` are read from different EC commands: - `max_response` is from cros_ec_get_proto_info(). ec_dev->max_response = info->max_response_packet_size - sizeof(struct ec_host_response); - `sensor_num` is from cros_ec_get_sensor_count(). sensor_num = cros_ec_get_sensor_count(ec); With a malfunctioning EC firmware, it is possible that the `msg->insize` (i.e., `fifo_info_length` in the context) could be clamped in cros_ec_cmd_xfer() because `msg->insize` is greater than `max_response`. int fifo_info_length = sizeof(struct ec_response_motion_sense_fifo_info) + sizeof(u16) * sensorhub->sensor_num; This means the number of read bytes could be less than expected. As a result, the subsequent memcpy() in cros_ec_sensorhub_ring_handler() overreads the `resp->fifo_info` buffer. Check the return value of cros_ec_cmd_xfer_status() and abort if the number of bytes read does not match the expected length.

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 145d59baff5944b71551ac518d7fd7d377a9c820 98604cc8fd2578442f49cd113481e8fc83bc0ad3 git Not specified
CNA Linux Linux affected 145d59baff5944b71551ac518d7fd7d377a9c820 86bcfab7dff6f0a61cbe0660e5176e907353141b git Not specified
CNA Linux Linux affected 145d59baff5944b71551ac518d7fd7d377a9c820 7e901aaf95828364b05a2120a1bea1a1669bdc9a git Not specified
CNA Linux Linux affected 145d59baff5944b71551ac518d7fd7d377a9c820 7780d93ae28f31fe517417c9451255315d1ad584 git Not specified
CNA Linux Linux affected 145d59baff5944b71551ac518d7fd7d377a9c820 ee0403520cdbcf87e853df9aaa9b518a0684ed38 git Not specified
CNA Linux Linux affected 145d59baff5944b71551ac518d7fd7d377a9c820 847a5ba0ac75f609e3f88da905251f7a76179145 git Not specified
CNA Linux Linux affected 145d59baff5944b71551ac518d7fd7d377a9c820 6268f46d83875d294d75b68b97a5b79953744598 git Not specified
CNA Linux Linux affected 145d59baff5944b71551ac518d7fd7d377a9c820 d1ceb2b2324717fa30b44d56ef0c52813e239569 git Not specified
CNA Linux Linux affected 5.7 Not specified
CNA Linux Linux unaffected 5.7 semver Not specified
CNA Linux Linux unaffected 5.10.270 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.221 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.188 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.157 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.110 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.52 6.18.* semver Not specified
CNA Linux Linux unaffected 7.2.6 7.2.* semver Not specified
CNA Linux Linux unaffected 7.3-rc1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/86bcfab7dff6f0a61cbe0660e5176e907353141b 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/7780d93ae28f31fe517417c9451255315d1ad584 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/d1ceb2b2324717fa30b44d56ef0c52813e239569 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/ee0403520cdbcf87e853df9aaa9b518a0684ed38 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/6268f46d83875d294d75b68b97a5b79953744598 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/98604cc8fd2578442f49cd113481e8fc83bc0ad3 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/7e901aaf95828364b05a2120a1bea1a1669bdc9a 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/847a5ba0ac75f609e3f88da905251f7a76179145 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report