CVE-2026-89470

Source
https://cve.org/CVERecord?id=CVE-2026-89470
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89470.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89470
Downstream
Published
2026-09-11T19:43:29Z
Modified
2026-09-13T03:47:18Z
Summary
power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS
Details

In the Linux kernel, the following vulnerability has been resolved:

power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS

Currently the cros_usbpd-charger driver probe iterates based on raw charger port count returned by the embedded controller. The only check is against the number of USB PD ports which the embedded controller also defines. A malicious embedded controller could return an inaccurate port count (up to 255) resulting in an out of bounds write and subsequent memory corruption.

Update helper functions in cros_usbpd-charger to limit port counts to EC_USB_PD_MAX_PORTS.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89470.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
3af15cfacd1eef7f223802d49a88cae23c509183
Fixed
fd5f289cca04ad869b34fc9ccb647670bfdb60ac
Fixed
4b1f2be1e1b74a50386ba718de3d62bfcf5ee701
Fixed
304a29ac55ba3ee6eceaf7d83d09cd9709f3bf60
Fixed
657cd3a42e937276262c0a8ae6b01a87004309de

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89470.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
6.12.109
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.50
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89470.json"