CVE-2026-93188

Source
https://cve.org/CVERecord?id=CVE-2026-93188
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93188.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93188
Downstream
Published
2026-09-17T16:12:13Z
Modified
2026-09-19T03:47:28Z
Summary
HID: roccat: bound device-supplied profile index
Details

In the Linux kernel, the following vulnerability has been resolved:

HID: roccat: bound device-supplied profile index

kone_keep_values_up_to_date() and kone_profile_activated() use an 8-bit, device-supplied profile value as an index into the 5-element kone->profiles[] array without a range check. A malicious USB device claiming the Roccat Kone id can send a switch-profile event (or a startup_profile read at probe) with an out-of-range value and make the driver read out of bounds; the result is exposed via the actual_dpi sysfs attribute.

Reject out-of-range indices in both paths.

This was found with static analysis and confirmed with the KUnit test added in the following patch (KASAN: slab-out-of-bounds).

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93188.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
14bf62cde79423a02a590e02664ed29a36facec1
Fixed
686e5c3bd378933b4e795fcc7d40c5aad358eaaa
Fixed
0a139188a7ce4baab7acc5d60e0d1c8657f9b4d4
Fixed
67d7851f113fd0205dd27416d3c47ab32b176097
Fixed
4b29be4b23bc28f59def1485702887e395256e11
Fixed
579c78c8c317ecff8b6b820c227c93e6ec4e565d
Fixed
635914c60da26a9892f27ffb5edcc922a10effab
Fixed
99330b12376c3373ab555c24bc797630f03b81a2
Fixed
43fae42628a8c10fa8981773d7ec9f1a367821a7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93188.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.35
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93188.json"