CVE-2026-23092Disclosure(linux / linux_kernel)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: iio: dac: ad3552r-hs: fix out-of-bound write in ad3552r_hs_write_data_source When simple_write_to_buffer() succeeds, it returns the number of bytes actually copied to the buffer. The code incorrectly uses 'count' as the index for null termination instead of the actual bytes copied. If count exceeds the buffer size, this leads to out-of-bounds write. Add a check for the count and use the return value as the index. The bug was validated using a demo module that mirrors the original code and was tested under QEMU. Pattern of the bug: - A fixed 64-byte stack buffer is filled using count. - If count > 64, the code still does buf[count] = '\0', causing an - out-of-bounds write on the stack. Steps for reproduce: - Opens the device node. - Writes 128 bytes of A to it. - This overflows the 64-byte stack buffer and KASAN reports the OOB. Found via static analysis. This is similar to the commit da9374819eb3 ("iio: backend: fix out-of-bound write")

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-02-05); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-05: 1Mentions · 2026-04-02: 1Mentions · 2026-04-04: 1Technical Details · 2026-02-05: 1Technical Details · 2026-04-02: 1Technical Details · 2026-04-04: 102-0504-0204-04
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Full discourse3 posts
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-250|CVE-2026-23092] Linux Kernel Analog Device Driver Improper Validation of Array Index Local Privilege Escalation Vulnerability (CVSS 8.2; Credit: Lucas Leong (@_wmliang_) of Trend Zero Day Initiative) https://www.zerodayinitiative.com/advisories/ZDI-26-250/

    Post summary

    An advisory has been published for CVE‑2026‑23092, describing a Linux kernel privilege‑escalation flaw caused by improper array index validation, rated CVSS 8.2.

    00051818
    5.5K followersView on X
  • SystemTek - Technology news website@SystemTek_UK
    Disclosure

    Linux Kernel Analog Device Driver Improper Validation of Array Index Local Privilege Escalation Vulnerability (CVE-2026-23092) #CVE202623092 #CyberSecurity #Linux #LinuxKernel #PrivilegeEscalationVulnerability https://www.systemtek.co.uk/?p=48998 https://t.co/rDPLWTxUbJ

    Post summary

    This post announces a new Linux Kernel vulnerability (CVE‑2026‑23092) involving improper array index validation that enables local privilege escalation.

    0000081
    1.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-23092 Out-of-Bounds Write in Linux Kernel IIO DAC AD3552R-HS Driver https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-23092 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    A brief alert announcing CVE-2026-23092, an out‑of‑bounds write vulnerability in the Linux kernel IIO DAC AD3552R-HS driver, with links to the CVE details but no exploitation or patch information.

    00000101
    4.0K followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel6.19--
OSlinuxlinux_kernel6.19--
OSlinuxlinux_kernel6.19--
OSlinuxlinux_kernel6.19--
OSlinuxlinux_kernel6.19--
OSlinuxlinux_kernel6.19--

Explore more