-
CVE-2026-93188
- EPSS 0.2%
- Veröffentlicht 17.09.2026 16:12:13
- Zuletzt bearbeitet 17.09.2026 17:18:14
- Erkennungen
HID: roccat: bound device-supplied profile index
In the Linux kernel, the following vulnerability has been resolved: HID: roccat: bound device-supplied profile index kone_keep_values_up_to_date() and kone_profile_activated() use an 8-bit, device-supplied profile value as an index into the 5-element kone->profiles[] array without a range check. A malicious USB device claiming the Roccat Kone id can send a switch-profile event (or a startup_profile read at probe) with an out-of-range value and make the driver read out of bounds; the result is exposed via the actual_dpi sysfs attribute. Reject out-of-range indices in both paths. This was found with static analysis and confirmed with the KUnit test added in the following patch (KASAN: slab-out-of-bounds).
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
14bf62cde79423a02a590e02664ed29a36facec1
Version <
686e5c3bd378933b4e795fcc7d40c5aad358eaaa
Status
affected
Version
14bf62cde79423a02a590e02664ed29a36facec1
Version <
0a139188a7ce4baab7acc5d60e0d1c8657f9b4d4
Status
affected
Version
14bf62cde79423a02a590e02664ed29a36facec1
Version <
67d7851f113fd0205dd27416d3c47ab32b176097
Status
affected
Version
14bf62cde79423a02a590e02664ed29a36facec1
Version <
4b29be4b23bc28f59def1485702887e395256e11
Status
affected
Version
14bf62cde79423a02a590e02664ed29a36facec1
Version <
579c78c8c317ecff8b6b820c227c93e6ec4e565d
Status
affected
Version
14bf62cde79423a02a590e02664ed29a36facec1
Version <
635914c60da26a9892f27ffb5edcc922a10effab
Status
affected
Version
14bf62cde79423a02a590e02664ed29a36facec1
Version <
99330b12376c3373ab555c24bc797630f03b81a2
Status
affected
Version
14bf62cde79423a02a590e02664ed29a36facec1
Version <
43fae42628a8c10fa8981773d7ec9f1a367821a7
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
2.6.35
Status
affected
Version
0
Version <
2.6.35
Status
unaffected
Version <=
5.10.*
Version
5.10.270
Status
unaffected
Version <=
5.15.*
Version
5.15.221
Status
unaffected
Version <=
6.1.*
Version
6.1.188
Status
unaffected
Version <=
6.6.*
Version
6.6.157
Status
unaffected
Version <=
6.12.*
Version
6.12.110
Status
unaffected
Version <=
6.18.*
Version
6.18.52
Status
unaffected
Version <=
7.2.*
Version
7.2.6
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.096 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/686e5c3bd378933b4e795fcc7d40c5aad358eaaa
https://git.kernel.org/stable/c/0a139188a7ce4baab7acc5d60e0d1c8657f9b4d4
https://git.kernel.org/stable/c/67d7851f113fd0205dd27416d3c47ab32b176097
https://git.kernel.org/stable/c/4b29be4b23bc28f59def1485702887e395256e11
https://git.kernel.org/stable/c/579c78c8c317ecff8b6b820c227c93e6ec4e565d
https://git.kernel.org/stable/c/635914c60da26a9892f27ffb5edcc922a10effab
https://git.kernel.org/stable/c/99330b12376c3373ab555c24bc797630f03b81a2
https://git.kernel.org/stable/c/43fae42628a8c10fa8981773d7ec9f1a367821a7