-
CVE-2026-63895
- EPSS 0.24%
- Veröffentlicht 19.07.2026 14:55:05
- Zuletzt bearbeitet 27.07.2026 17:44:23
- CVE-Watchlists
- Unerledigt
usb: gadget: f_fs: copy only received bytes on short ep0 read
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: f_fs: copy only received bytes on short ep0 read
ffs_ep0_read() allocates its control-OUT data buffer with
kmalloc() (not kzalloc) at the Length value from the Setup
packet, then copies that full len to userspace regardless of
how many bytes were actually received:
data = kmalloc(len, GFP_KERNEL);
...
ret = __ffs_ep0_queue_wait(ffs, data, len);
if ((ret > 0) && (copy_to_user(buf, data, len)))
ret = -EFAULT;
__ffs_ep0_queue_wait() returns req->actual, which on a short
control OUT transfer is strictly less than len. The
copy_to_user() call still copies len bytes, so on a short OUT
the last (len - ret) bytes of the kmalloc() buffer --
uninitialised slab residue -- are delivered to the FunctionFS
daemon.
Short ep0 OUT completions are specified USB control-transfer
behavior and are produced by in-tree UDCs:
* dwc2 continues on req->actual < req->length for ep0 DATA OUT
(short-not-ok is the only ep0-OUT stall path).
* aspeed_udc ends ep0 OUT on rx_len < ep->ep.maxpacket.
* renesas_usbf logs "ep0 short packet" and completes the
request.
* dwc3 stalls on short IN but not on short OUT.
A short ep0 OUT is therefore not evidence of a broken UDC; it is
a normal condition f_fs has to cope with. The sibling gadgetfs
implementation in drivers/usb/gadget/legacy/inode.c already does
this correctly via min(len, dev->req->actual) before
copy_to_user(). This patch brings f_fs.c to the same safe
pattern rather than trimming at a defensive layer.
The bug is reached from the FunctionFS device node, which in
real deployments is owned by the privileged gadget daemon
(adbd, UMS, composite gadget services, etc.); it is not
reachable from unprivileged userspace. Linux host stacks
normally reject short-wLength control OUTs before they reach
the gadget, so reproducing this required a build that
bypasses that host-side check. With the bypass in place, a
1-byte payload on a 64-byte Setup produces 63 bytes of
non-canary slab residue in the daemon's read buffer.
Fix by copying only ret (actually received) bytes to
userspace.Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
ddf8abd2599491cbad959c700b90ba72a5dce8d0
Version <
90ccf5fb63243fae1b4b3200f3310500500ecf2e
Status
affected
Version
ddf8abd2599491cbad959c700b90ba72a5dce8d0
Version <
af32dbb2ca0b3d09271ab718d13857a457fa16f2
Status
affected
Version
ddf8abd2599491cbad959c700b90ba72a5dce8d0
Version <
e835bf9a055f71874065a40780ca5560b7df8b33
Status
affected
Version
ddf8abd2599491cbad959c700b90ba72a5dce8d0
Version <
88874a19b2b093bfaaa1c0090fa536c44da8c08b
Status
affected
Version
ddf8abd2599491cbad959c700b90ba72a5dce8d0
Version <
607730a414773a7cbe3037a64a6c64e72689ff5e
Status
affected
Version
ddf8abd2599491cbad959c700b90ba72a5dce8d0
Version <
23c1f7deb9dd8447ecde749850676302aa1e2bd3
Status
affected
Version
ddf8abd2599491cbad959c700b90ba72a5dce8d0
Version <
4e036c10e7f4df5d951c69cc3697bc8e209c6d02
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
2.6.35
Status
affected
Version
0
Version <
2.6.35
Status
unaffected
Version <=
5.15.*
Version
5.15.210
Status
unaffected
Version <=
6.1.*
Version
6.1.176
Status
unaffected
Version <=
6.6.*
Version
6.6.143
Status
unaffected
Version <=
6.12.*
Version
6.12.93
Status
unaffected
Version <=
6.18.*
Version
6.18.35
Status
unaffected
Version <=
7.0.*
Version
7.0.12
Status
unaffected
Version <=
*
Version
7.1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.24% | 0.156 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/90ccf5fb63243fae1b4b3200f3310500500ecf2e
https://git.kernel.org/stable/c/af32dbb2ca0b3d09271ab718d13857a457fa16f2
https://git.kernel.org/stable/c/e835bf9a055f71874065a40780ca5560b7df8b33
https://git.kernel.org/stable/c/88874a19b2b093bfaaa1c0090fa536c44da8c08b
https://git.kernel.org/stable/c/607730a414773a7cbe3037a64a6c64e72689ff5e
https://git.kernel.org/stable/c/23c1f7deb9dd8447ecde749850676302aa1e2bd3
https://git.kernel.org/stable/c/4e036c10e7f4df5d951c69cc3697bc8e209c6d02