CVE-2026-89470

8.4

Linux · Kernel

A memory corruption vulnerability in the Linux kernel cros_usbpd-charger driver allows a malicious embedded controller to trigger an out of bounds write via an inaccurate port count.

Executive summary

A high-severity memory corruption vulnerability in the Linux kernel cros_usbpd-charger driver could allow a malicious hardware controller to execute arbitrary code or cause system instability.

Vulnerability

The vulnerability exists in the cros_usbpd-charger driver, which fails to properly validate the charger port count returned by an embedded controller. An attacker with control over the embedded controller can provide a malicious value, leading to an out of bounds memory write and subsequent system-level memory corruption.

Business impact

A successful exploit of this vulnerability could lead to a complete system compromise or denial of service. Given the CVSS score of 8.4, this flaw poses a significant risk to system integrity and availability, particularly in environments where hardware components are shared or untrusted. Unauthorized code execution at the kernel level allows for total control over the affected device, potentially leading to data exfiltration or persistent backdoor installation.

Remediation

Immediate Action: Update the Linux kernel to version 6.12.109, 6.18.50, 7.2.4, or later depending on your active maintenance branch.

Proactive Monitoring: Monitor system logs for kernel panics or unexpected hardware initialization errors related to the cros_usbpd-charger driver.

Compensating Controls: Ensure that only trusted hardware and firmware are used in the device supply chain to prevent the introduction of malicious embedded controllers that could trigger this driver flaw.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This vulnerability represents a critical security risk due to the potential for kernel-level memory corruption. Organizations running affected versions of the Linux kernel should prioritize applying the provided upstream patches. Failure to patch may leave systems susceptible to exploitation by compromised hardware controllers, which could result in full system compromise.

More Linux CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. Analyst report written
  4. Published in the daily brief high section

Sources