CVE-2026-89470: power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS

Published Sep 11, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

power: supply: crosusbpd: Limit port counts to ECUSBPDMAXPORTS

Currently the crosusbpd-charger driver probe iterates based on raw charger port count returned by the embedded controller. The only check is against the number of USB PD ports which the embedded controller also defines. A malicious embedded controller could return an inaccurate port count (up to 255) resulting in an out of bounds write and subsequent memory corruption.

Update helper functions in crosusbpd-charger to limit port counts to ECUSBPDMAXPORTS.

Affected Software

1 affected component
Linux Linux kernel

Event History

Sep 11, 2026
CVE Published
via MITRE·07:43 PM
Data Sourced
via MITRE·07:43 PM
Description

Frequently Asked Questions

1

What must an attacker control to trigger this issue?

An attacker would need a malicious or compromised embedded controller that reports an inaccurate charger port count. The vulnerable driver uses that raw count during probe, allowing a value up to 255 to lead to an out-of-bounds write and memory corruption.

2

Which systems are realistically exposed?

Exposure is limited to Linux kernel systems using the cros_usbpd-charger driver and an embedded controller that supplies the charger port-count data. Systems without this driver path or without a malicious embedded controller are not described as affected.

3

What can be done if the kernel fix cannot be applied immediately?

The provided information identifies the embedded controller's reported port count as the attack source. A practical interim measure is to prevent use of untrusted or compromised embedded-controller firmware; no driver configuration workaround is provided.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203