๐Ÿ” CVE Alert

CVE-2026-81017

HIGH 8.4

platform/chrome: sensorhub: Bound the EC-reported sensor number

CVSS Score
8.4
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: platform/chrome: sensorhub: Bound the EC-reported sensor number Each EC FIFO event carries an 8-bit sensor number (in->sensor_num). cros_ec_sensorhub_ring_handler() validates the FIFO event count, the per-read count and the ring bound, but not the sensor number, which cros_ec_sensor_ring_process_event() then uses unchecked to index sensorhub->batch_state[] - allocated with only sensorhub->sensor_num entries. A sensor number of sensor_num or larger is an out-of-bounds read and write of batch_state[]. Validate the sensor number in the ring handler, where each event is read from the EC, and drop a malformed event before it is used.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
145d59baff5944b71551ac518d7fd7d377a9c820 < 3a76b87e1d065183e2e7ae5b800cb1f6e84f543d 145d59baff5944b71551ac518d7fd7d377a9c820 < 2b602ecf6193ecb9720c78b6728d7e09370b1ff1 145d59baff5944b71551ac518d7fd7d377a9c820 < 324880f94ba3c6269a607e04f78a4dd4a66b3f53 145d59baff5944b71551ac518d7fd7d377a9c820 < d1b4add68dabfdd6481a4fa198bf3b473d2634d7 145d59baff5944b71551ac518d7fd7d377a9c820 < 3d2636dce0a8fe9eecad29010699847be425dc80 145d59baff5944b71551ac518d7fd7d377a9c820 < 5eaf7faa99578ae090030d1e2e6ea3b37a615496 145d59baff5944b71551ac518d7fd7d377a9c820 < 4d9bf63ed74f859c6698bc01d8fb216ef9253867 145d59baff5944b71551ac518d7fd7d377a9c820 < 833740a2333c2e4db4e02e3d0ffba04e8718a5f3
Linux / Linux
5.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/3a76b87e1d065183e2e7ae5b800cb1f6e84f543d git.kernel.org: https://git.kernel.org/stable/c/2b602ecf6193ecb9720c78b6728d7e09370b1ff1 git.kernel.org: https://git.kernel.org/stable/c/324880f94ba3c6269a607e04f78a4dd4a66b3f53 git.kernel.org: https://git.kernel.org/stable/c/d1b4add68dabfdd6481a4fa198bf3b473d2634d7 git.kernel.org: https://git.kernel.org/stable/c/3d2636dce0a8fe9eecad29010699847be425dc80 git.kernel.org: https://git.kernel.org/stable/c/5eaf7faa99578ae090030d1e2e6ea3b37a615496 git.kernel.org: https://git.kernel.org/stable/c/4d9bf63ed74f859c6698bc01d8fb216ef9253867 git.kernel.org: https://git.kernel.org/stable/c/833740a2333c2e4db4e02e3d0ffba04e8718a5f3