CVE-2026-93053 PUBLISHED

speakup: keyhelp: guard letter_offsets possible out-of-range indexing

Assigner: Linux
Reserved: 17.09.2026 Published: 17.09.2026 Updated: 17.09.2026

In the Linux kernel, the following vulnerability has been resolved:

speakup: keyhelp: guard letter_offsets possible out-of-range indexing

help_init() builds letter_offsets[] by using the first byte of each function name as an index via (start & 31) - 1. If function_names are overridden from sysfs (root) with a name starting outside [a–z], the index underflows or exceeds the array, leading to OOB write.

Function names can be overridden with the following commands as root:

<pre>modprobe speakup_soft echo "0 _bad" > /sys/accessibility/speakup/i18n/function_names # then press Insert+2 on /dev/tty </pre>

This fix checks the first letter in help_init(), and if it is not in the [a–z] range the function returns an error to the caller. Eventually this error is propagated to drivers/accessibility/speakup/main.c:2217, which causes a bleep sound.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from c6e3fd22cd538365bfeb82997d5b89562e077d42 to fd339b9ef0accb2c24a5285df842552ebf5eb146 (excl.)
  • affected from c6e3fd22cd538365bfeb82997d5b89562e077d42 to 900cd6e5ef46bd15153762fb26bb03f874fccc52 (excl.)
  • affected from c6e3fd22cd538365bfeb82997d5b89562e077d42 to 6b39969c724d39b6062efa354dc2d38442bfd021 (excl.)
  • affected from c6e3fd22cd538365bfeb82997d5b89562e077d42 to 2e91ab73f9beb659f581e2a6a09f79ace1140905 (excl.)
  • affected from c6e3fd22cd538365bfeb82997d5b89562e077d42 to d7deb90c4cd086cb111f0ecc9da021218fbde1b0 (excl.)
  • affected from c6e3fd22cd538365bfeb82997d5b89562e077d42 to 5310334762c3f08f51dc2414344dd47492c07d1d (excl.)
  • affected from c6e3fd22cd538365bfeb82997d5b89562e077d42 to ca4489b3e54666a7cac7294e71a3cf64e5e95286 (excl.)
  • affected from c6e3fd22cd538365bfeb82997d5b89562e077d42 to 6a19ad4d68c95185308cd9e5d169b10a2cf236c8 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 2.6.37 is affected
  • unaffected from 0 to 2.6.37 (excl.)
  • unaffected from 5.10.270 to 5.10.* (incl.)
  • unaffected from 5.15.221 to 5.15.* (incl.)
  • unaffected from 6.1.188 to 6.1.* (incl.)
  • unaffected from 6.6.157 to 6.6.* (incl.)
  • unaffected from 6.12.110 to 6.12.* (incl.)
  • unaffected from 6.18.52 to 6.18.* (incl.)
  • unaffected from 7.2.6 to 7.2.* (incl.)
  • unaffected from 7.3-rc1 to * (incl.)

References