CVE-2026-90328

Source
https://cve.org/CVERecord?id=CVE-2026-90328
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90328.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90328
Downstream
Published
2026-09-17T16:08:42Z
Modified
2026-09-18T03:48:37Z
Summary
HID: steam: Reject short reads
Details

In the Linux kernel, the following vulnerability has been resolved:

HID: steam: Reject short reads

Steam Controller FEATURE reports encode the size of the message in the message itself. Previously we were trusting that the size reported matched the size we actually read, leading to a potential issue with short reads. Instead, we should actually verify the length of the read.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90328.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
c164d6abf3841ffacfdb757c10616f9cb1f67276
Fixed
f694ea0ead544080949e409a7c6885ee1fc77a98
Fixed
93c5cc35bcd9f62db589a21945b49691dccdd99d
Fixed
33ff7b49c38b39b1f3d27db508ac0720fb25c08a

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90328.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.18.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90328.json"