CVE-2026-89471
Received Received - Intake

Bounds Check Bypass in Linux Kernel cros_usbpd-charger

Vulnerability report for CVE-2026-89471, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: power: supply: cros_usbpd-charger: bound the EC-reported port count cros_usbpd_charger_probe() reads two port counts from the EC and uses one of them, num_charger_ports, as the loop bound when populating a fixed-size array: struct port_data *ports[EC_USB_PD_MAX_PORTS]; /* 8 entries */ ... for (i = 0; i < charger->num_charger_ports; i++) charger->ports[charger->num_registered_psy++] = port; Both num_usbpd_ports (from EC_CMD_USB_PD_PORTS) and num_charger_ports (from EC_CMD_CHARGE_PORT_COUNT) are u8 values reported by the EC. The only validation is a sanity check that compares the two EC-reported values against each other: if (num_charger_ports < num_usbpd_ports || num_charger_ports > num_usbpd_ports + 1) return -EPROTO; It never checks either count against EC_USB_PD_MAX_PORTS, the size of the ports[] array. A malfunctioning, malicious or compromised EC that reports num_usbpd_ports == num_charger_ports == N for any N > 8 (for example both 255) passes this check, and the loop then writes N pointers into the 8-entry ports[] array embedded in the devm_kzalloc()'d charger_data, overflowing it by up to 255 - 8 = 247 entries (~1976 bytes): a slab out-of-bounds write. Reject a port count larger than the ports[] array can hold.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a vulnerability in the Linux kernel's power supply subsystem, specifically in the cros_usbpd-charger driver. It involves a lack of bounds checking when reading port counts from the EC (Embedded Controller). The driver uses a fixed-size array of 8 entries but does not validate that the reported port count is within this limit. A malicious or compromised EC could report a port count exceeding 8, causing a buffer overflow when writing pointers into the array.

Detection Guidance

This vulnerability is specific to the Linux kernel's power supply subsystem for ChromeOS USB-PD chargers. Detection requires checking the kernel version and examining the cros_usbpd-charger module. Inspect kernel logs for errors related to port count mismatches or slab overflows. Commands: dmesg | grep cros_usbpd, modinfo cros_usbpd-charger, and checking kernel version with uname -r.

Impact Analysis

This vulnerability could lead to memory corruption, crashes, or arbitrary code execution on systems using the affected Linux kernel component. An attacker with access to the EC could exploit this to gain elevated privileges or cause denial-of-service conditions.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it is a low-level kernel memory corruption issue in the Linux power supply subsystem. Compliance impacts would only occur if this vulnerability were exploited to cause system instability, data corruption, or unauthorized access, which is not described in the provided context.

Mitigation Strategies

Apply the latest kernel update that includes the fix for this issue. If an update is unavailable, disable the cros_usbpd-charger module temporarily by running rmmod cros_usbpd-charger. Monitor vendor advisories for patches and avoid using untrusted USB-PD chargers.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89471. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart