CVE-2026-89628
CVE CVE-2026-89628EUVD EUVD-2026-76540Published 2026-09-11T19:45:24.000ZLast changed 2026-09-14T12:01:39.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: HID: picolcd: clamp eeprom debugfs read to bytes actually received picolcd_debug_eeprom_read() trusts resp->raw_data[2] -- a length byte supplied by the device in its REPORT_EE_DATA reply -- clamped only to the caller's read() count: ret = resp->raw_data[2]; if (ret > s) ret = s; if (copy_to_user(u, resp->raw_data+3, ret)) It never checks resp->raw_size, the number of bytes picolcd_raw_event() actually copied into the 64-byte raw_data[] of the kmalloc'd struct picolcd_pending. A device (or a spoofed picoLCD) returning a length byte of 0xff, read with a count >= 255, makes copy_to_user() read past raw_data[] into adjacent slab memory and return it to userspace through the debugfs "eeprom" file: BUG: KASAN: slab-out-of-bounds in _copy_to_user Read of size 255 ... picolcd_debug_eeprom_read+0x214/0x2f0 [hid_picolcd] The debug-dump path in the same file already validates the device length byte against the received size before trusting it; this read does not. The file is created S_IRUSR (root-only) and a crafted device is needed, so it is neither unprivileged- nor remotely-triggerable. Clamp the copy length to resp->raw_size - 3 (the payload actually received, minus the 3-byte header), floored at 0 for short replies.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 2.6.35; 9bbf2b98ba11d00bd73e3254e15cfe17ccaff6ba <e9c667395ac1f8024f623250b32bae4c7af9caa0; 9bbf2b98ba11d00bd73e3254e15cfe17ccaff6ba <4daf432c94a42e7be6aa10b012b33af5ed9bc118; patch: 6.18.50; patch: 6.1.188; 9bbf2b98ba11d00bd73e3254e15cfe17ccaff6ba <699a3c8b56e168ca19d12722f3f5ef1d6f4b1d84; patch: 5.15.221; 9bbf2b98ba11d00bd73e3254e15cfe17ccaff6ba <65daa322f1021d8206f8032c4cd4c0cb2d26c7c3; 9bbf2b98ba11d00bd73e3254e15cfe17ccaff6ba <a3e6e8d7198a9f3861861520a38b673684a1062b; patch: 7.3-rc1; patch: 6.6.157; patch: 7.2.4; 9bbf2b98ba11d00bd73e3254e15cfe17ccaff6ba <1a02056c2bf7ef9b5fd05ee6913aeeadb703c443; patch: 0; patch: 6.12.109; 9bbf2b98ba11d00bd73e3254e15cfe17ccaff6ba <8dc662af019158690c470edd2e2857657f700abb; patch: 5.10.270; 9bbf2b98ba11d00bd73e3254e15cfe17ccaff6ba <471f4a939c66d1d44aece2321807abf609fc9098
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.