0.0
NA
CVE-2026-93188
HID: roccat: bound device-supplied profile index
Description

In the Linux kernel, the following vulnerability has been resolved: HID: roccat: bound device-supplied profile index kone_keep_values_up_to_date() and kone_profile_activated() use an 8-bit, device-supplied profile value as an index into the 5-element kone->profiles[] array without a range check. A malicious USB device claiming the Roccat Kone id can send a switch-profile event (or a startup_profile read at probe) with an out-of-range value and make the driver read out of bounds; the result is exposed via the actual_dpi sysfs attribute. Reject out-of-range indices in both paths. This was found with static analysis and confirmed with the KUnit test added in the following patch (KASAN: slab-out-of-bounds).

INFO

Published Date :

Sept. 17, 2026, 5:18 p.m.

Last Modified :

Sept. 17, 2026, 5:18 p.m.

Remotely Exploit :

No

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-93188 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

No affected product recoded yet

Solution
Ensure device profile indices are validated to prevent out-of-bounds reads.
  • Apply the patch to validate profile indices.
  • Update the Linux kernel to the patched version.
  • Validate device profile index ranges.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-93188 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-93188 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-93188 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-93188 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Sep. 17, 2026

    Action Type Old Value New Value
    Added Description In the Linux kernel, the following vulnerability has been resolved: HID: roccat: bound device-supplied profile index kone_keep_values_up_to_date() and kone_profile_activated() use an 8-bit, device-supplied profile value as an index into the 5-element kone->profiles[] array without a range check. A malicious USB device claiming the Roccat Kone id can send a switch-profile event (or a startup_profile read at probe) with an out-of-range value and make the driver read out of bounds; the result is exposed via the actual_dpi sysfs attribute. Reject out-of-range indices in both paths. This was found with static analysis and confirmed with the KUnit test added in the following patch (KASAN: slab-out-of-bounds).
    Added Affected New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/93xxx/CVE-2026-93188.json">CVE-2026-93188</a>
    Added Reference https://git.kernel.org/stable/c/0a139188a7ce4baab7acc5d60e0d1c8657f9b4d4
    Added Reference https://git.kernel.org/stable/c/43fae42628a8c10fa8981773d7ec9f1a367821a7
    Added Reference https://git.kernel.org/stable/c/4b29be4b23bc28f59def1485702887e395256e11
    Added Reference https://git.kernel.org/stable/c/579c78c8c317ecff8b6b820c227c93e6ec4e565d
    Added Reference https://git.kernel.org/stable/c/635914c60da26a9892f27ffb5edcc922a10effab
    Added Reference https://git.kernel.org/stable/c/67d7851f113fd0205dd27416d3c47ab32b176097
    Added Reference https://git.kernel.org/stable/c/686e5c3bd378933b4e795fcc7d40c5aad358eaaa
    Added Reference https://git.kernel.org/stable/c/99330b12376c3373ab555c24bc797630f03b81a2
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.