-

CVE-2026-93053

speakup: keyhelp: guard letter_offsets possible out-of-range indexing

In the Linux kernel, the following vulnerability has been resolved:

speakup: keyhelp: guard letter_offsets possible out-of-range indexing

help_init() builds letter_offsets[] by using the first byte of each
function name as an index via `(start & 31) - 1`. If function_names are
overridden from sysfs (root) with a name starting outside [a–z], the
index underflows or exceeds the array, leading to OOB write.

Function names can be overridden with the following commands as root:

    modprobe speakup_soft
    echo "0 _bad" > /sys/accessibility/speakup/i18n/function_names
    # then press Insert+2 on /dev/tty

This fix checks the first letter in help_init(), and if it is not in the
[a–z] range the function returns an error to the caller. Eventually this
error is propagated to drivers/accessibility/speakup/main.c:2217, which
causes a bleep sound.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version c6e3fd22cd538365bfeb82997d5b89562e077d42
Version < fd339b9ef0accb2c24a5285df842552ebf5eb146
Status affected
Version c6e3fd22cd538365bfeb82997d5b89562e077d42
Version < 900cd6e5ef46bd15153762fb26bb03f874fccc52
Status affected
Version c6e3fd22cd538365bfeb82997d5b89562e077d42
Version < 6b39969c724d39b6062efa354dc2d38442bfd021
Status affected
Version c6e3fd22cd538365bfeb82997d5b89562e077d42
Version < 2e91ab73f9beb659f581e2a6a09f79ace1140905
Status affected
Version c6e3fd22cd538365bfeb82997d5b89562e077d42
Version < d7deb90c4cd086cb111f0ecc9da021218fbde1b0
Status affected
Version c6e3fd22cd538365bfeb82997d5b89562e077d42
Version < 5310334762c3f08f51dc2414344dd47492c07d1d
Status affected
Version c6e3fd22cd538365bfeb82997d5b89562e077d42
Version < ca4489b3e54666a7cac7294e71a3cf64e5e95286
Status affected
Version c6e3fd22cd538365bfeb82997d5b89562e077d42
Version < 6a19ad4d68c95185308cd9e5d169b10a2cf236c8
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.37
Status affected
Version 0
Version < 2.6.37
Status unaffected
Version <= 5.10.*
Version 5.10.270
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.075
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/fd339b9ef0accb2c24a5285df842552ebf5eb146
https://git.kernel.org/stable/c/900cd6e5ef46bd15153762fb26bb03f874fccc52
https://git.kernel.org/stable/c/6b39969c724d39b6062efa354dc2d38442bfd021
https://git.kernel.org/stable/c/2e91ab73f9beb659f581e2a6a09f79ace1140905
https://git.kernel.org/stable/c/d7deb90c4cd086cb111f0ecc9da021218fbde1b0
https://git.kernel.org/stable/c/5310334762c3f08f51dc2414344dd47492c07d1d
https://git.kernel.org/stable/c/ca4489b3e54666a7cac7294e71a3cf64e5e95286
https://git.kernel.org/stable/c/6a19ad4d68c95185308cd9e5d169b10a2cf236c8