{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89470","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.710Z","datePublished":"2026-09-11T19:43:29.206Z","dateUpdated":"2026-09-14T12:00:07.466Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T12:00:07.466Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\npower: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS\n\nCurrently the cros_usbpd-charger driver probe iterates based on raw\ncharger port count returned by the embedded controller. The only check\nis against the number of USB PD ports which the embedded controller\nalso defines. A malicious embedded controller could return an inaccurate\nport count (up to 255) resulting in an out of bounds write and\nsubsequent memory corruption.\n\nUpdate helper functions in cros_usbpd-charger to limit port counts to\nEC_USB_PD_MAX_PORTS."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The OOB write is in cros_usbpd_charger_probe() on the Chrome OS EC platform path (LPC/eSPI/I2C/SPI/UART/ISHTP → cros_ec_cmd_xfer_status → MFD cell cros-usbpd-charger). Port counts come from the onboard EC, not from network packets or a USB-C partner, so the highest defensible vector is local.\nAC:L - A malicious or compromised EC fully controls both u8 replies (EC_CMD_USB_PD_PORTS and EC_CMD_CHARGE_PORT_COUNT). Setting them equal and greater than 8 (for example both 255) passes the relative sanity check and makes the probe loop overflow ports[EC_USB_PD_MAX_PORTS] deterministically, with no race or layout lottery.\nPR:N - ec_device_probe() auto-adds the charger cell when the EC advertises USB-PD and probe then trusts EC replies with no Linux capability or credential check. Supply-chain or already-compromised EC firmware needs no host account, matching other firmware-at-probe kernel CNA scores.\nUI:N - The charger driver probes automatically during Chrome OS EC MFD bring-up at boot or module load. No victim action such as plugging a cable, mounting a filesystem, or opening a device node is required.\nS:U - Impact is kernel slab corruption and possible code execution on the same host that runs the charger driver. This is not a VM escape, IOMMU/DMA boundary bypass, or other cross-authority breakout.\nC:H - The probe writes up to 247 pointers past the 8-entry ports[] array in the kmalloc'd charger_data (about 1976 bytes on 64-bit), corrupting adjacent slab objects. That heap overflow can be turned into an arbitrary-read primitive, not a small bounded leak.\nI:H - The overflow stores attacker-timed port_data pointers past ports[] (and can also overflow each port's name[] via sprintf for i>=10), enabling adjacent-object corruption, control-flow hijack, and arbitrary write.\nA:H - Smashing charger_data's trailing notifier_block and neighboring slab objects during probe can oops or panic the kernel on Chromebooks and other Chrome OS EC systems, a full availability loss."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/power/supply/cros_usbpd-charger.c"],"versions":[{"version":"3af15cfacd1eef7f223802d49a88cae23c509183","lessThan":"e951b65ef1699439079b723ca5c72cbe44771647","status":"affected","versionType":"git"},{"version":"3af15cfacd1eef7f223802d49a88cae23c509183","lessThan":"3ce9218639ff62d011eb8aca0943aa670a654c7b","status":"affected","versionType":"git"},{"version":"3af15cfacd1eef7f223802d49a88cae23c509183","lessThan":"dce1750ddbd3380b1f6090dda2b07d2ebea2261d","status":"affected","versionType":"git"},{"version":"3af15cfacd1eef7f223802d49a88cae23c509183","lessThan":"3262977a05b23d1be9fc86727a2b490ec997543e","status":"affected","versionType":"git"},{"version":"3af15cfacd1eef7f223802d49a88cae23c509183","lessThan":"fd5f289cca04ad869b34fc9ccb647670bfdb60ac","status":"affected","versionType":"git"},{"version":"3af15cfacd1eef7f223802d49a88cae23c509183","lessThan":"4b1f2be1e1b74a50386ba718de3d62bfcf5ee701","status":"affected","versionType":"git"},{"version":"3af15cfacd1eef7f223802d49a88cae23c509183","lessThan":"304a29ac55ba3ee6eceaf7d83d09cd9709f3bf60","status":"affected","versionType":"git"},{"version":"3af15cfacd1eef7f223802d49a88cae23c509183","lessThan":"657cd3a42e937276262c0a8ae6b01a87004309de","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/power/supply/cros_usbpd-charger.c"],"versions":[{"version":"4.20","status":"affected"},{"version":"0","lessThan":"4.20","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.20","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.20","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.20","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.20","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.20","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.20","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.20","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.20","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/e951b65ef1699439079b723ca5c72cbe44771647"},{"url":"https://git.kernel.org/stable/c/3ce9218639ff62d011eb8aca0943aa670a654c7b"},{"url":"https://git.kernel.org/stable/c/dce1750ddbd3380b1f6090dda2b07d2ebea2261d"},{"url":"https://git.kernel.org/stable/c/3262977a05b23d1be9fc86727a2b490ec997543e"},{"url":"https://git.kernel.org/stable/c/fd5f289cca04ad869b34fc9ccb647670bfdb60ac"},{"url":"https://git.kernel.org/stable/c/4b1f2be1e1b74a50386ba718de3d62bfcf5ee701"},{"url":"https://git.kernel.org/stable/c/304a29ac55ba3ee6eceaf7d83d09cd9709f3bf60"},{"url":"https://git.kernel.org/stable/c/657cd3a42e937276262c0a8ae6b01a87004309de"}],"title":"power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS","x_generator":{"engine":"bippy-1.2.0"}}}}