HID: roccat: bound device-supplied profile index
Summary
| CVE | CVE-2026-93188 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-17 17:18:14 UTC |
| Updated | 2026-09-17 17:18:14 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
HID: roccat: bound device-supplied profile index
kone_keep_values_up_to_date() and kone_profile_activated() use an
8-bit, device-supplied profile value as an index into the 5-element
kone->profiles[] array without a range check. A malicious USB device
claiming the Roccat Kone id can send a switch-profile event (or a
startup_profile read at probe) with an out-of-range value and make the
driver read out of bounds; the result is exposed via the actual_dpi
sysfs attribute.
Reject out-of-range indices in both paths.
This was found with static analysis and confirmed with the KUnit test
added in the following patch (KASAN: slab-out-of-bounds). |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 14bf62cde79423a02a590e02664ed29a36facec1 686e5c3bd378933b4e795fcc7d40c5aad358eaaa git |
Not specified |
| CNA |
Linux |
Linux |
affected 14bf62cde79423a02a590e02664ed29a36facec1 0a139188a7ce4baab7acc5d60e0d1c8657f9b4d4 git |
Not specified |
| CNA |
Linux |
Linux |
affected 14bf62cde79423a02a590e02664ed29a36facec1 67d7851f113fd0205dd27416d3c47ab32b176097 git |
Not specified |
| CNA |
Linux |
Linux |
affected 14bf62cde79423a02a590e02664ed29a36facec1 4b29be4b23bc28f59def1485702887e395256e11 git |
Not specified |
| CNA |
Linux |
Linux |
affected 14bf62cde79423a02a590e02664ed29a36facec1 579c78c8c317ecff8b6b820c227c93e6ec4e565d git |
Not specified |
| CNA |
Linux |
Linux |
affected 14bf62cde79423a02a590e02664ed29a36facec1 635914c60da26a9892f27ffb5edcc922a10effab git |
Not specified |
| CNA |
Linux |
Linux |
affected 14bf62cde79423a02a590e02664ed29a36facec1 99330b12376c3373ab555c24bc797630f03b81a2 git |
Not specified |
| CNA |
Linux |
Linux |
affected 14bf62cde79423a02a590e02664ed29a36facec1 43fae42628a8c10fa8981773d7ec9f1a367821a7 git |
Not specified |
| CNA |
Linux |
Linux |
affected 2.6.35 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 2.6.35 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.10.270 5.10.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.15.221 5.15.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.1.188 6.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.157 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.110 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.52 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2.6 7.2.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.3-rc1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/43fae42628a8c10fa8981773d7ec9f1a367821a7 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/0a139188a7ce4baab7acc5d60e0d1c8657f9b4d4 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/4b29be4b23bc28f59def1485702887e395256e11 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/67d7851f113fd0205dd27416d3c47ab32b176097 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/635914c60da26a9892f27ffb5edcc922a10effab |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/99330b12376c3373ab555c24bc797630f03b81a2 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/579c78c8c317ecff8b6b820c227c93e6ec4e565d |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/686e5c3bd378933b4e795fcc7d40c5aad358eaaa |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.