CVE-2026-93213
Published Sep 24, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: of: fix out-of-bounds read in of_alias_scan() stem parser The stem parser tests isdigit(*(end - 1)) before checking end > start and so reads one byte before the property name when the name is empty or all digits. Check the bound first.
Is your site exposed to CVE-2026-93213?
Run a free security scan — no signup, results in seconds.
References
Other References
https://git.kernel.org/stable/c/5bb01c657ff9fc807c2c592ca18af34c4fc3bc6f
https://git.kernel.org/stable/c/9253cfc5a85be1494ce56b4fc6f2d2b509440910
https://git.kernel.org/stable/c/958d7ee9fcf008ef9d2072c6410ee1bf6abf3b64
https://git.kernel.org/stable/c/96a9c984dd7c3589a2707a32b62802f98311dbfd
https://git.kernel.org/stable/c/acd1b49043366f43e932308b4db7d3ce568eeadb
https://git.kernel.org/stable/c/da7a80ddc610a19b0378016a4d816b9355f013a7
https://git.kernel.org/stable/c/f7f6c3e32a31f2e1ed12075e8cd22b370a84e67a
https://git.kernel.org/stable/c/fd0c7bbda81c0e0c1cb7b68d267b87371584f560
Frequently Asked Questions
What is CVE-2026-93213? +
In the Linux kernel, the following vulnerability has been resolved:
of: fix out-of-bounds read in of_alias_scan() stem parser
The stem parser tests isdigit(*(end - 1)) before checking end > start
and so reads one byte before the property name when the name is empty
or all digits. Check the bound first.
How do I check if I'm vulnerable to CVE-2026-93213? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.