# CVE-2026-89628

## Summary

- **CVE ID:** CVE-2026-89628
- **Severity:** UNKNOWN
- **CVSS Score:** 0
- **CWE:** N/A
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 16, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

HID: picolcd: clamp eeprom debugfs read to bytes actually received

picolcd_debug_eeprom_read() trusts resp->raw_data[2] -- a length byte
supplied by the device in its REPORT_EE_DATA reply -- clamped only to
the caller's read() count:

	ret = resp->raw_data[2];
	if (ret > s)
		ret = s;
	if (copy_to_user(u, resp->raw_data+3, ret))

It never checks resp->raw_size, the number of bytes picolcd_raw_event()
actually copied into the 64-byte raw_data[] of the kmalloc'd struct
picolcd_pending. A device (or a spoofed picoLCD) returning a length byte
of 0xff, read with a count >= 255, makes copy_to_user() read past
raw_data[] into adjacent slab memory and return it to userspace through
the debugfs "eeprom" file:

	BUG: KASAN: slab-out-of-bounds in _copy_to_user
	Read of size 255 ... picolcd_debug_eeprom_read+0x214/0x2f0 [hid_picolcd]

The debug-dump path in the same file already validates the device length
byte against the received size before trusting it; this read does not.
The file is created S_IRUSR (root-only) and a crafted device is needed,
so it is neither unprivileged- nor remotely-triggerable.

Clamp the copy length to resp->raw_size - 3 (the payload actually
received, minus the 3-byte header), floored at 0 for short replies.

## Affected Products

- Linux — Linux (9bbf2b98ba11d00bd73e3254e15cfe17ccaff6ba)
- Linux — Linux (2.6.35)
- Linux — Linux (0)
- Linux — Linux (6.12.109)
- Linux — Linux (6.18.50)
- Linux — Linux (7.2.4)
- Linux — Linux (7.3-rc1)
- Linux — Linux (5.10.270)
- Linux — Linux (5.15.221)
- Linux — Linux (6.1.188)
- Linux — Linux (6.6.157)

## References

- [CNA](https://git.kernel.org/stable/c/a3e6e8d7198a9f3861861520a38b673684a1062b)
- [CNA](https://git.kernel.org/stable/c/471f4a939c66d1d44aece2321807abf609fc9098)
- [CNA](https://git.kernel.org/stable/c/699a3c8b56e168ca19d12722f3f5ef1d6f4b1d84)
- [CNA](https://git.kernel.org/stable/c/e9c667395ac1f8024f623250b32bae4c7af9caa0)
- [CNA](https://git.kernel.org/stable/c/1a02056c2bf7ef9b5fd05ee6913aeeadb703c443)
- [CNA](https://git.kernel.org/stable/c/65daa322f1021d8206f8032c4cd4c0cb2d26c7c3)
- [CNA](https://git.kernel.org/stable/c/8dc662af019158690c470edd2e2857657f700abb)
- [CNA](https://git.kernel.org/stable/c/4daf432c94a42e7be6aa10b012b33af5ed9bc118)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.22%
- **EPSS Percentile:** 12.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._