-

CVE-2026-43427

usb: class: cdc-wdm: fix reordering issue in read code path

In the Linux kernel, the following vulnerability has been resolved:

usb: class: cdc-wdm: fix reordering issue in read code path

Quoting the bug report:

Due to compiler optimization or CPU out-of-order execution, the
desc->length update can be reordered before the memmove. If this
happens, wdm_read() can see the new length and call copy_to_user() on
uninitialized memory. This also violates LKMM data race rules [1].

Fix it by using WRITE_ONCE and memory barriers.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version afba937e540c902c989cd516fd97ea0c8499bb27
Version < 638328ca9c17ae6511ad62198c57bae32ffa3c91
Status affected
Version afba937e540c902c989cd516fd97ea0c8499bb27
Version < 170e8daca24da6edb4be82ab01abf44e87af387b
Status affected
Version afba937e540c902c989cd516fd97ea0c8499bb27
Version < c8fa96ed021923dae147bcd9f9205b8df7b82360
Status affected
Version afba937e540c902c989cd516fd97ea0c8499bb27
Version < 4ee3062bf2c9a722afef429826e8607eaf3fc6a0
Status affected
Version afba937e540c902c989cd516fd97ea0c8499bb27
Version < 276aef0fd2b92f41b920ac891c72cadeee957934
Status affected
Version afba937e540c902c989cd516fd97ea0c8499bb27
Version < 67ed312124bb1b61858778ac0b985b48961c862a
Status affected
Version afba937e540c902c989cd516fd97ea0c8499bb27
Version < e3c874b05901dc519054b5107d16620e6d2b5fea
Status affected
Version afba937e540c902c989cd516fd97ea0c8499bb27
Version < 8df672bfe3ec2268c2636584202755898e547173
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 2.6.26
Status affected
Version 0
Version < 2.6.26
Status unaffected
Version <= 5.10.*
Version 5.10.253
Status unaffected
Version <= 5.15.*
Version 5.15.203
Status unaffected
Version <= 6.1.*
Version 6.1.167
Status unaffected
Version <= 6.6.*
Version 6.6.130
Status unaffected
Version <= 6.12.*
Version 6.12.78
Status unaffected
Version <= 6.18.*
Version 6.18.19
Status unaffected
Version <= 6.19.*
Version 6.19.9
Status unaffected
Version <= *
Version 7.0
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.03% 0.091
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.