Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-93188— HID: roccat: bound device-supplied profile index

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: HID:roccat:对设备提供的配置文件索引进行边界检查 和 函数使用一个 8 位、由设备提供的配置文件值作为索引,直接访问长度为 5 的 数组,但未进行范围检查。一个声称具有 Roccat Kone 设备 ID 的恶意 USB 设备可以发送一个越界的“切换配置文件”事件(或在探测阶段读取 时发送越界值),从而导致驱动程序发生越界读取。该越界读取的结果会通过 sysfs 属性暴露出来。 在两条处理路径中,均拒绝越界的索引值。 此漏洞是通过静态分析发现的,并通过后续补丁中添

AI Predicted 5.1 Difficulty: Moderate EPSS 0.20% · P10

Possible ATT&CK Techniques 1 AI

T1059.001 · PowerShell

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux 14bf62cde79423a02a590e02664ed29a36facec1< 686e5c3bd378933b4e795fcc7d40c5aad358eaaa affected
14bf62cde79423a02a590e02664ed29a36facec1< 0a139188a7ce4baab7acc5d60e0d1c8657f9b4d4 affected
14bf62cde79423a02a590e02664ed29a36facec1< 67d7851f113fd0205dd27416d3c47ab32b176097 affected
14bf62cde79423a02a590e02664ed29a36facec1< 4b29be4b23bc28f59def1485702887e395256e11 affected
14bf62cde79423a02a590e02664ed29a36facec1< 579c78c8c317ecff8b6b820c227c93e6ec4e565d affected
14bf62cde79423a02a590e02664ed29a36facec1< 635914c60da26a9892f27ffb5edcc922a10effab affected
14bf62cde79423a02a590e02664ed29a36facec1< 99330b12376c3373ab555c24bc797630f03b81a2 affected
14bf62cde79423a02a590e02664ed29a36facec1< 43fae42628a8c10fa8981773d7ec9f1a367821a7 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-93188

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
HID: roccat: bound device-supplied profile index
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: HID: roccat: bound device-supplied profile index kone_keep_values_up_to_date() and kone_profile_activated() use an 8-bit, device-supplied profile value as an index into the 5-element kone->profiles[] array without a range check. A malicious USB device claiming the Roccat Kone id can send a switch-profile event (or a startup_profile read at probe) with an out-of-range value and make the driver read out of bounds; the result is exposed via the actual_dpi sysfs attribute. Reject out-of-range indices in both paths. This was found with static analysis and confirmed with the KUnit test added in the following patch (KASAN: slab-out-of-bounds).
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 14bf62cde79423a02a590e02664ed29a36facec1 ~ 686e5c3bd378933b4e795fcc7d40c5aad358eaaa -
Linux Linux 2.6.35 -

II. Public POCs for CVE-2026-93188

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-93188

登录查看更多情报信息。

Patches & Fixes for CVE-2026-93188 (8)

Same Patch Batch · Linux · 2026-09-17 · 600 CVEs total

CVE-2026-92489 9.8 CRITICAL xfrm: Fix skb double-free in xfrm_dev_direct_output()
CVE-2026-90151 9.8 CRITICAL NFSv4: remove callback IDR entry on client allocation failure
CVE-2026-90235 9.8 CRITICAL sunrpc: xprtsock: annotate shared socket callbacks with READ_ONCE/WRITE_ONCE
CVE-2026-90104 9.8 CRITICAL NFSv4.1: zero referring call lists before decoding
CVE-2026-90173 9.8 CRITICAL smb: smbdirect: free completion queues with ib_free_cq()
CVE-2026-90110 9.4 CRITICAL inetpeer: randomize RB-tree node comparison using SipHash
CVE-2026-90230 9.1 CRITICAL nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate()
CVE-2026-90413 9.1 CRITICAL IB/isert: reject login PDUs declaring more data than was received
CVE-2026-90414 9.1 CRITICAL IB/isert: reject PDUs declaring more data than was received
CVE-2026-90425 8.8 HIGH iommu/tegra241-cmdqv: Require exactly one Stream ID for a vSID
CVE-2026-93042 8.8 HIGH dmaengine: dw-edma: Terminate all descriptors without callbacks
CVE-2026-93189 8.8 HIGH HID: core: quiesce input in hid_hw_stop() to prevent use-after-free
CVE-2026-90329 8.8 HIGH HID: synchronize input before cleaning up a failed probe
CVE-2026-90357 8.8 HIGH wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement
CVE-2026-90256 8.8 HIGH Bluetooth: L2CAP: use proto_lock for l2cap_data to fix l2cap_disconn_ind
CVE-2026-90367 8.8 HIGH wifi: mt76: mt7996: hold dev->mt76.mutex while disabling tx worker in SER
CVE-2026-90381 8.8 HIGH wifi: mt76: fix handling channel context with different bands in mt76_switch_vif_chanctx()
CVE-2026-90379 8.8 HIGH wifi: mt76: mt7921: Add PCIe AER handler support to prevent system crash
CVE-2026-90380 8.8 HIGH wifi: mt76: mt792x: fix use-after-free in mt76_rx_poll_complete
CVE-2026-90371 8.8 HIGH wifi: mt76: fix RXDMAD_C buffer recycling race

Showing top 20 of 600 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-93188

No comments yet


Leave a comment