Executive brief
A vulnerability was identified in the Linux kernel's Qualcomm Light Pulse Generator (LPG) LED driver. This component manages LED lighting on certain Qualcomm-based hardware. An issue in how the driver reads hardware registers could lead to the system reading incorrect memory, potentially causing unpredictable behavior or system instability.
Technical details
An array out-of-bounds read vulnerability exists in the leds-qcom-lpg driver within the Linux kernel. The function lpg_pwm_get_state() uses FIELD_GET() to extract a 3-bit value from a hardware register to index the lpg_clk_rates_hi_res array. While a 3-bit field can represent values up to 7, the target array contains only 5 elements. If the hardware register returns a value of 5, 6, or 7, the driver would perform an out-of-bounds read. This could result in the driver using arbitrary data from kernel memory to configure hardware clock rates. The issue has been resolved by adding an explicit bounds check against ARRAY_SIZE(lpg_clk_rates_hi_res).
Affected products
- Linux Linux kernel All versions prior to the fix in leds-qcom-lpg.c
Timeline
- 2026-02-19: patched: Initial patch authored by Greg Kroah-Hartman
- 2026-06-08: disclosed: CVE published in NVD dataset
References
- https://git.kernel.org/stable/c/28a2e047d03721e0517c67ee726eaa6621c30e5f
- https://git.kernel.org/stable/c/36ce3094dc50598f38fd961b46688cd533940efc
- https://git.kernel.org/stable/c/438e357b3cc6cd6900df271e4bc567bfe1142281
- https://git.kernel.org/stable/c/d45963a93c1495e9f1338fde91d0ebba8fd22474
- https://git.kernel.org/stable/c/f67a24e75d3251ba42538738120b6b659c0dca7d