CVE-2026-93213

Source
https://cve.org/CVERecord?id=CVE-2026-93213
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93213.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93213
Downstream
Published
2026-09-24T15:10:36Z
Modified
2026-09-25T03:48:54Z
Summary
of: fix out-of-bounds read in of_alias_scan() stem parser
Details

In the Linux kernel, the following vulnerability has been resolved:

of: fix out-of-bounds read in of_alias_scan() stem parser

The stem parser tests isdigit(*(end - 1)) before checking end > start and so reads one byte before the property name when the name is empty or all digits. Check the bound first.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93213.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
611cad720148c899db5a383c1c676fd820df7023
Fixed
fd0c7bbda81c0e0c1cb7b68d267b87371584f560
Fixed
958d7ee9fcf008ef9d2072c6410ee1bf6abf3b64
Fixed
f7f6c3e32a31f2e1ed12075e8cd22b370a84e67a
Fixed
da7a80ddc610a19b0378016a4d816b9355f013a7
Fixed
96a9c984dd7c3589a2707a32b62802f98311dbfd
Fixed
9253cfc5a85be1494ce56b4fc6f2d2b509440910
Fixed
acd1b49043366f43e932308b4db7d3ce568eeadb
Fixed
5bb01c657ff9fc807c2c592ca18af34c4fc3bc6f

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93213.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.2.0
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.109
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.50
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93213.json"