-

CVE-2026-93120

usb: gadget: configfs: fix out-of-bounds read of qw_sign

In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: configfs: fix out-of-bounds read of qw_sign

os_desc_qw_sign_show() passes OS_STRING_QW_SIGN_LEN as the input
length to utf16s_to_utf8s(), but that argument counts UTF-16 code
units while OS_STRING_QW_SIGN_LEN (14) is the byte size of qw_sign[].
The array holds only OS_STRING_QW_SIGN_LEN / 2 (7) code units, so the
conversion reads up to 7 units (14 bytes) past the end of qw_sign[]
into the following members of struct gadget_info when the stored
signature fills the array without a NUL terminator, exposing those
bytes through the configfs attribute.

The store path halves the count for its input bound but passes the
full byte count as the utf8s_to_utf16s() output limit; use the
destination code-unit count in both directions.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 76180d716f91f035d9c8639497cf5459b44e1a51
Version < b895dbed8ac9e12a5ffa1a2165575a8469f8340d
Status affected
Version 76180d716f91f035d9c8639497cf5459b44e1a51
Version < 9b45125501aad2dff7730970461b455b0e0658ee
Status affected
Version 76180d716f91f035d9c8639497cf5459b44e1a51
Version < f6da500b0f8106882598b6dec87fe37d653946cf
Status affected
Version 76180d716f91f035d9c8639497cf5459b44e1a51
Version < a28c486434634f6d1e120711d2b09f3eddea6c98
Status affected
Version 76180d716f91f035d9c8639497cf5459b44e1a51
Version < 7e94cb967778e074411940db4db97f22ed77560c
Status affected
Version 76180d716f91f035d9c8639497cf5459b44e1a51
Version < afbf39c0f2297c6abef6d670a82a2079b0836191
Status affected
Version 76180d716f91f035d9c8639497cf5459b44e1a51
Version < 36315a330e067f7773196940552feacb1debbef1
Status affected
Version 76180d716f91f035d9c8639497cf5459b44e1a51
Version < f63edb54d8f738f9c21e2068c777ae1c097df6b7
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.13
Status affected
Version 0
Version < 4.13
Status unaffected
Version <= 5.10.*
Version 5.10.270
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.116
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/b895dbed8ac9e12a5ffa1a2165575a8469f8340d
https://git.kernel.org/stable/c/9b45125501aad2dff7730970461b455b0e0658ee
https://git.kernel.org/stable/c/f6da500b0f8106882598b6dec87fe37d653946cf
https://git.kernel.org/stable/c/a28c486434634f6d1e120711d2b09f3eddea6c98
https://git.kernel.org/stable/c/7e94cb967778e074411940db4db97f22ed77560c
https://git.kernel.org/stable/c/afbf39c0f2297c6abef6d670a82a2079b0836191
https://git.kernel.org/stable/c/36315a330e067f7773196940552feacb1debbef1
https://git.kernel.org/stable/c/f63edb54d8f738f9c21e2068c777ae1c097df6b7