← All Advisories

Linux Kernel HID Roccat Driver Uses an 8-bit Device-Supplied Profile Value as an Array Index Without Bounds Checking, Enabling an Out-of-Bounds Memory Access via a Crafted USB Device

Last refreshed2026-09-28

Status: NEW  |  Advisory ID: CVE-2026-93188

Key Details

CVECVE-2026-93188

What to Know

In the Linux kernel, the following vulnerability has been resolved:

HID: roccat: bound device-supplied profile index

kone_keep_values_up_to_date() and kone_profile_activated() use an

8-bit, device-supplied profile value as an index into the 5-element

kone->profiles[] array without a range check. A malicious USB device

claiming the Roccat Kone id can send a switch-profile event (or a

startup_profile read at probe) with an out-of-range value and make the

driver read out of bounds; the result is exposed via the actual_dpi

sysfs attribute.

Reject out-of-range indices in both paths.

This was found with static analysis and confirmed with the KUnit test

added in the following patch (KASAN: slab-out-of-bounds). (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-93188
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-93188