-
CVE-2026-63943
- EPSS 0.2%
- Veröffentlicht 19.07.2026 14:55:38
- Zuletzt bearbeitet 27.07.2026 17:44:23
- CVE-Watchlists
- Unerledigt
Input: xpad - fix out-of-bounds access for Share button
In the Linux kernel, the following vulnerability has been resolved: Input: xpad - fix out-of-bounds access for Share button xpadone_process_packet() receives len directly from urb->actual_length and uses it to index the share-button byte at data[len - 18] or data[len - 26]. Since both len and data[0] are under the device's control, a broken controller can send a GIP_CMD_INPUT packet with actual_length < 18 (e.g. 5 bytes) and reach this code path, causing accesses beyond the actual array. Fix this by calculating the offset and checking bounds against the packet length.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
cbc82e7db16d59c301457312a624a7de2c03cd4a
Version <
bcfb4833cd4078a1a356ef451838b75cd233099e
Status
affected
Version
302a0cd0bbc450998429a3f4267970a4b93251a8
Version <
37ec54abfdd63a63fd50734a9c4e4cbc1e5795af
Status
affected
Version
4ef46367073b107ec22f46fe5f12176e87c238e8
Version <
9749db57233b396353ad5dee81eec9d9880c9246
Status
affected
Version
4ef46367073b107ec22f46fe5f12176e87c238e8
Version <
6346b0895b574ce45f3747b9c508c72f70e6abef
Status
affected
Version
4ef46367073b107ec22f46fe5f12176e87c238e8
Version <
6cdc46b38cf146ce81d4831b6472dbf7731849a2
Status
affected
Version
a7e3ddd1d9a3d0b26465ed01d464e3c05479ebc8
Status
affected
Version
6.6.91
Version <
6.6.143
Status
affected
Version
6.12.29
Version <
6.12.93
Status
affected
Version
6.14.7
Version <
6.15
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.15
Status
affected
Version
0
Version <
6.15
Status
unaffected
Version <=
6.6.*
Version
6.6.143
Status
unaffected
Version <=
6.12.*
Version
6.12.93
Status
unaffected
Version <=
6.18.*
Version
6.18.35
Status
unaffected
Version <=
7.0.*
Version
7.0.12
Status
unaffected
Version <=
*
Version
7.1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.1 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/bcfb4833cd4078a1a356ef451838b75cd233099e
https://git.kernel.org/stable/c/37ec54abfdd63a63fd50734a9c4e4cbc1e5795af
https://git.kernel.org/stable/c/9749db57233b396353ad5dee81eec9d9880c9246
https://git.kernel.org/stable/c/6346b0895b574ce45f3747b9c508c72f70e6abef
https://git.kernel.org/stable/c/6cdc46b38cf146ce81d4831b6472dbf7731849a2