CVE-2026-89471Medium· 5.5▾ SunlitA flaw was found in the Linux kernel's `cros_usbpd-charger` driver. A malicious or compromised embedded controller (EC) can report an excessive number of USB Power Delivery (PD) ports. This causes the driver to write beyond the allocated m…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
— → 6.4
none → medium
— → 6.4
none → medium
— → 8.4
none → high
8.4 → 6.4
high → medium
6.4 → 8.4
medium → high
Last analysed / modified upstream
8.4 → 5.5
high → medium
A flaw was found in the Linux kernel's cros_usbpd-charger driver. A malicious or compromised embedded controller (EC) can report an excessive number of USB Power Delivery (PD) ports. This causes the driver to write beyond the allocated memory buffer when populating a fixed-size array for port data, leading to a slab out-of-bounds write. This memory corruption could potentially be exploited by a local attacker.
kernel: power: supply: cros_usbpd-charger: bound the EC-reported port count — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-18.
Not affected:
Refer to the advisory for fix availability.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-89436Medium· 5.5kernel: platform/x86: panasonic-laptop: Fix sentinel write past pcc->sinf[] (CVE-2026-89436)
CVE-2026-89610Medium· 5.5kernel: ntfs: verify run length exceeding volume boundary (CVE-2026-89610)
CVE-2026-89611Medium· 5.5kernel: ntfs: validate non-resident attribute offsets (CVE-2026-89611)
CVE-2026-89612Medium· 5.5kernel: ntfs: reject invalid MFT LCNs from boot sector (CVE-2026-89612)
CVE-2026-89513Medium· 5.5kernel: RISC-V: KVM: Fix PMU event info array size overflow (CVE-2026-89513)
CVE-2026-89748Medium· 5.5kernel: tracing: Fix retry exhaustion in simple ring buffer reader swap (CVE-2026-89748)