{"id":"CVE-2026-93213","summary":"of: fix out-of-bounds read in of_alias_scan() stem parser","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nof: fix out-of-bounds read in of_alias_scan() stem parser\n\nThe stem parser tests isdigit(*(end - 1)) before checking end \u003e start\nand so reads one byte before the property name when the name is empty\nor all digits. Check the bound first.","modified":"2026-09-25T03:48:54.500688116Z","published":"2026-09-24T15:10:36.166Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93213.json"},"references":[{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"},{"type":"WEB","url":"https://git.kernel.org/stable/c/5bb01c657ff9fc807c2c592ca18af34c4fc3bc6f"},{"type":"WEB","url":"https://git.kernel.org/stable/c/9253cfc5a85be1494ce56b4fc6f2d2b509440910"},{"type":"WEB","url":"https://git.kernel.org/stable/c/958d7ee9fcf008ef9d2072c6410ee1bf6abf3b64"},{"type":"WEB","url":"https://git.kernel.org/stable/c/96a9c984dd7c3589a2707a32b62802f98311dbfd"},{"type":"WEB","url":"https://git.kernel.org/stable/c/acd1b49043366f43e932308b4db7d3ce568eeadb"},{"type":"WEB","url":"https://git.kernel.org/stable/c/da7a80ddc610a19b0378016a4d816b9355f013a7"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f7f6c3e32a31f2e1ed12075e8cd22b370a84e67a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/fd0c7bbda81c0e0c1cb7b68d267b87371584f560"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93213.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93213"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"611cad720148c899db5a383c1c676fd820df7023"},{"fixed":"fd0c7bbda81c0e0c1cb7b68d267b87371584f560"},{"fixed":"958d7ee9fcf008ef9d2072c6410ee1bf6abf3b64"},{"fixed":"f7f6c3e32a31f2e1ed12075e8cd22b370a84e67a"},{"fixed":"da7a80ddc610a19b0378016a4d816b9355f013a7"},{"fixed":"96a9c984dd7c3589a2707a32b62802f98311dbfd"},{"fixed":"9253cfc5a85be1494ce56b4fc6f2d2b509440910"},{"fixed":"acd1b49043366f43e932308b4db7d3ce568eeadb"},{"fixed":"5bb01c657ff9fc807c2c592ca18af34c4fc3bc6f"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93213.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.2.0"},{"fixed":"5.10.270"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.221"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.188"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.157"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.109"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.50"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.2.4"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93213.json"}}],"schema_version":"1.9.0"}