-

CVE-2026-72074

Input: ims-pcu - fix type confusion in CDC union descriptor parsing

In the Linux kernel, the following vulnerability has been resolved:

Input: ims-pcu - fix type confusion in CDC union descriptor parsing

The driver currently trusts the bMasterInterface0 from the CDC union
descriptor without verifying that it matches the interface being
probed. This could lead to the driver overwriting the private data of
another interface.

Validate that the control interface found in the descriptor is indeed
the one we are probing.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 628329d52474323938a03826941e166bc7c8eff4
Version < ab87cd7789d00f441f60a016cbcff35abe76513c
Status affected
Version 628329d52474323938a03826941e166bc7c8eff4
Version < b5518c5632f3485849421b9c33b4db5ae6a54ed7
Status affected
Version 628329d52474323938a03826941e166bc7c8eff4
Version < 163c3e7a1de6b3d5c85edb3bdf4cf087382103b0
Status affected
Version 628329d52474323938a03826941e166bc7c8eff4
Version < 08bf4b6ee28987570f4b3f1954427621fa291bf5
Status affected
Version 628329d52474323938a03826941e166bc7c8eff4
Version < fa7f65c5315a25b310daae69ab527efd420e37fa
Status affected
Version 628329d52474323938a03826941e166bc7c8eff4
Version < 0e8115a7ed9a99ff9495615a575a6c0f43566d10
Status affected
Version 628329d52474323938a03826941e166bc7c8eff4
Version < f4cf878dcc4f6f02e7a25294bfaed4361264995e
Status affected
Version 628329d52474323938a03826941e166bc7c8eff4
Version < ca459e237bc49567649c56bc72e4c602fb92fd67
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.10
Status affected
Version 0
Version < 3.10
Status unaffected
Version <= 5.10.*
Version 5.10.261
Status unaffected
Version <= 5.15.*
Version 5.15.212
Status unaffected
Version <= 6.1.*
Version 6.1.178
Status unaffected
Version <= 6.6.*
Version 6.6.145
Status unaffected
Version <= 6.12.*
Version 6.12.97
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.128
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/ab87cd7789d00f441f60a016cbcff35abe76513c
https://git.kernel.org/stable/c/b5518c5632f3485849421b9c33b4db5ae6a54ed7
https://git.kernel.org/stable/c/163c3e7a1de6b3d5c85edb3bdf4cf087382103b0
https://git.kernel.org/stable/c/08bf4b6ee28987570f4b3f1954427621fa291bf5
https://git.kernel.org/stable/c/fa7f65c5315a25b310daae69ab527efd420e37fa
https://git.kernel.org/stable/c/0e8115a7ed9a99ff9495615a575a6c0f43566d10
https://git.kernel.org/stable/c/f4cf878dcc4f6f02e7a25294bfaed4361264995e
https://git.kernel.org/stable/c/ca459e237bc49567649c56bc72e4c602fb92fd67