« Volver al listado

CVE-2026-74681

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

usb: misc: usbio: check ibuf_len against rxbuf_len in bulk msg

ibuf_len is the bulk IN (receive) buffer size, but the EMSGSIZE check in usbio_bulk_msg() compares it against txbuf_len — the bulk OUT endpoint size. Both are taken independently from different endpoints in usbio_probe(), so the check is wrong when they differ.

Use rxbuf_len for the IN direction. This matches the buffer that actually holds the response data.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-74681",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "121a0f839dbb397af5fabb701cea3e9983223e50",
              "lessThan": "ebfd1e82ab0a6d26efd9bdd89de899215851f5bf",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "121a0f839dbb397af5fabb701cea3e9983223e50",
              "lessThan": "9ad0164f78b66b0b5eca3a5748cc94dd87e28124",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "121a0f839dbb397af5fabb701cea3e9983223e50",
              "lessThan": "7e22c9f79b200672f3e477421b6c9050d8cf70a5",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/usb/misc/usbio.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.18"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.18",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.45",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.9",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/usb/misc/usbio.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-22T16:16:42.373",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/7e22c9f79b200672f3e477421b6c9050d8cf70a5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9ad0164f78b66b0b5eca3a5748cc94dd87e28124",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ebfd1e82ab0a6d26efd9bdd89de899215851f5bf",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: misc: usbio: check ibuf_len against rxbuf_len in bulk msg\n\nibuf_len is the bulk IN (receive) buffer size, but the EMSGSIZE check\nin usbio_bulk_msg() compares it against txbuf_len — the bulk OUT\nendpoint size.  Both are taken independently from different endpoints\nin usbio_probe(), so the check is wrong when they differ.\n\nUse rxbuf_len for the IN direction.  This matches the buffer that\nactually holds the response data."
    }
  ],
  "lastModified": "2026-08-22T16:16:42.373",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}