{"id":"CVE-2026-90328","published":"2026-09-17T17:17:30.940","lastModified":"2026-09-17T17:17:30.940","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: steam: Reject short reads\n\nSteam Controller FEATURE reports encode the size of the message in the\nmessage itself. Previously we were trusting that the size reported matched\nthe size we actually read, leading to a potential issue with short reads.\nInstead, we should actually verify the length of the read.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/33ff7b49c38b39b1f3d27db508ac0720fb25c08a","tags":[]},{"url":"https://git.kernel.org/stable/c/93c5cc35bcd9f62db589a21945b49691dccdd99d","tags":[]},{"url":"https://git.kernel.org/stable/c/f694ea0ead544080949e409a7c6885ee1fc77a98","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}