CVE-2026-89628
Received Received - Intake

Buffer Overflow in Linux Kernel HID picolcd Driver

Vulnerability report for CVE-2026-89628, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: HID: picolcd: clamp eeprom debugfs read to bytes actually received picolcd_debug_eeprom_read() trusts resp->raw_data[2] -- a length byte supplied by the device in its REPORT_EE_DATA reply -- clamped only to the caller's read() count: ret = resp->raw_data[2]; if (ret > s) ret = s; if (copy_to_user(u, resp->raw_data+3, ret)) It never checks resp->raw_size, the number of bytes picolcd_raw_event() actually copied into the 64-byte raw_data[] of the kmalloc'd struct picolcd_pending. A device (or a spoofed picoLCD) returning a length byte of 0xff, read with a count >= 255, makes copy_to_user() read past raw_data[] into adjacent slab memory and return it to userspace through the debugfs "eeprom" file: BUG: KASAN: slab-out-of-bounds in _copy_to_user Read of size 255 ... picolcd_debug_eeprom_read+0x214/0x2f0 [hid_picolcd] The debug-dump path in the same file already validates the device length byte against the received size before trusting it; this read does not. The file is created S_IRUSR (root-only) and a crafted device is needed, so it is neither unprivileged- nor remotely-triggerable. Clamp the copy length to resp->raw_size - 3 (the payload actually received, minus the 3-byte header), floored at 0 for short replies.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Linux kernel's HID picolcd driver. It involves a flaw in the picolcd_debug_eeprom_read() function where it trusts a length byte from a device without properly validating it against the actual data received. This can lead to reading past the allocated memory into adjacent slab memory, causing a slab-out-of-bounds read error.

Detection Guidance

This vulnerability is specific to the Linux kernel's HID picolcd driver and requires local access to a system with the vulnerable driver loaded. Detection involves checking for the presence of the picolcd_debug_eeprom_read function in the kernel and verifying if the system is running a vulnerable kernel version. Use commands like 'lsmod | grep picolcd' to check if the driver is loaded and 'uname -a' to check the kernel version.

Impact Analysis

This vulnerability requires a crafted device and root access to exploit. It could allow local users with root privileges to read sensitive kernel memory, potentially exposing confidential data. However, it is not remotely exploitable or accessible to unprivileged users.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards. The issue is a local, root-only slab out-of-bounds read in the Linux kernel's HID picolcd driver, requiring a crafted device and debugfs access. It does not involve unauthorized data access, data breaches, or exposure of sensitive information that would typically trigger compliance violations under these regulations.

Mitigation Strategies

Immediately update your Linux kernel to a patched version that includes the fix for CVE-2026-89628. If updating is not immediately possible, consider unloading the picolcd kernel module with 'modprobe -r hid-picolcd' to disable the vulnerable driver until a patch can be applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89628. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart