CVE-2026-90328 PUBLISHED

HID: steam: Reject short reads

Assigner: Linux
Reserved: 11.09.2026 Published: 17.09.2026 Updated: 17.09.2026

In the Linux kernel, the following vulnerability has been resolved:

HID: steam: Reject short reads

Steam Controller FEATURE reports encode the size of the message in the message itself. Previously we were trusting that the size reported matched the size we actually read, leading to a potential issue with short reads. Instead, we should actually verify the length of the read.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from c164d6abf3841ffacfdb757c10616f9cb1f67276 to f694ea0ead544080949e409a7c6885ee1fc77a98 (excl.)
  • affected from c164d6abf3841ffacfdb757c10616f9cb1f67276 to 93c5cc35bcd9f62db589a21945b49691dccdd99d (excl.)
  • affected from c164d6abf3841ffacfdb757c10616f9cb1f67276 to 33ff7b49c38b39b1f3d27db508ac0720fb25c08a (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 4.18 is affected
  • unaffected from 0 to 4.18 (excl.)
  • unaffected from 6.18.52 to 6.18.* (incl.)
  • unaffected from 7.2.6 to 7.2.* (incl.)
  • unaffected from 7.3-rc1 to * (incl.)

References