« Volver al listado

CVE-2026-68344

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect

uea_probe() distinguishes a pre-firmware device from a post-firmware one using the USB id (UEA_IS_PREFIRM()), and stores a different object as the interface data in each case: a 'struct completion' for a pre-firmware device (to be waited on in .disconnect()), or a 'struct usbatm_data' for a post-firmware one.

uea_disconnect() instead tells the two apart by the number of interfaces of the active configuration (a pre-firmware device exposes a single interface, ADI930 has 2 and eagle has 3), and casts the interface data accordingly.

Leer descripción completaMostrar menos

Because the two handlers use different criteria, a crafted device that advertises a pre-firmware id together with a multi-interface descriptor (or a post-firmware id with a single interface) makes them disagree: the small 'struct completion' stored by uea_probe() is then passed to usbatm_usb_disconnect(), which casts it to 'struct usbatm_data' and takes instance->serialize, reading past the end of the allocation:

Reject such inconsistent descriptors in uea_probe() so that both handlers always make the same pre/post-firmware decision.

Detalles técnicos trazas, registros y código del informe original
  BUG: KASAN: slab-out-of-bounds in __mutex_lock+0x152a/0x1b80
  Read of size 8 at addr ffff8880470e2c60 by task kworker/1:2/982
  ...
   __mutex_lock+0x152a/0x1b80
   usbatm_usb_disconnect+0x70/0x820
   uea_disconnect+0x133/0x2c0
   usb_unbind_interface+0x1dd/0x9e0
  ...
  which belongs to the cache kmalloc-96 of size 96
  The buggy address is located 0 bytes to the right of
   allocated 96-byte region [ffff8880470e2c00, ffff8880470e2c60)

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-68344",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "d85f19aaef42a03e3e4765d659c761c8750a7f23",
              "lessThan": "9e7312844429379108ea9523a5ed934f142bb177",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "76861031b43a18065d13f9ffb8595d25c7576005",
              "lessThan": "f92832262718443feb4e5df2bf70424ba842629e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "bbfedc84714064ea4845e6b76f96316eb5bb65d8",
              "lessThan": "e814ae925f6f575325124c29dde518b92c822b83",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f2a6abc670104fc3e383ee3b1cf35c070485e3df",
              "lessThan": "c035b1198906dd5bd3df9a3045b59254bad1ea7a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c581e30ae5b332d8acef64475a211b3f82099941",
              "lessThan": "9904a46401198872ab3de34fd11f383831ef3428",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "509b51327320bdeaef1969248177a446ded073ab",
              "lessThan": "d0a57f19fe2865b9747484f5f9c631f944ed9a0f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ddcdac47e1f2651c7be60e299f98faf981522797",
              "lessThan": "0cc0c4c14150bb5a16b88dd61368f96cd4caa9ce",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e2674dfbed8a30d57e2bc872c4bfa6c3eec918bf",
              "lessThan": "71132cedd1ecbc4032d76e9928c18a10f7e39b80",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/usb/atm/ueagle-atm.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.10.261",
              "lessThan": "5.10.265",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.15.212",
              "lessThan": "5.15.216",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.1.178",
              "lessThan": "6.1.183",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.6.145",
              "lessThan": "6.6.148",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.12.97",
              "lessThan": "6.12.101",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.18.40",
              "lessThan": "6.18.42",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "7.1.5",
              "lessThan": "7.1.6",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "drivers/usb/atm/ueagle-atm.c"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-08-10T13:20:24.947",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0cc0c4c14150bb5a16b88dd61368f96cd4caa9ce",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/71132cedd1ecbc4032d76e9928c18a10f7e39b80",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9904a46401198872ab3de34fd11f383831ef3428",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9e7312844429379108ea9523a5ed934f142bb177",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c035b1198906dd5bd3df9a3045b59254bad1ea7a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d0a57f19fe2865b9747484f5f9c631f944ed9a0f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e814ae925f6f575325124c29dde518b92c822b83",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f92832262718443feb4e5df2bf70424ba842629e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect\n\nuea_probe() distinguishes a pre-firmware device from a post-firmware one\nusing the USB id (UEA_IS_PREFIRM()), and stores a different object as the\ninterface data in each case: a 'struct completion' for a pre-firmware\ndevice (to be waited on in .disconnect()), or a 'struct usbatm_data' for a\npost-firmware one.\n\nuea_disconnect() instead tells the two apart by the number of interfaces\nof the active configuration (a pre-firmware device exposes a single\ninterface, ADI930 has 2 and eagle has 3), and casts the interface data\naccordingly.\n\nBecause the two handlers use different criteria, a crafted device that\nadvertises a pre-firmware id together with a multi-interface descriptor\n(or a post-firmware id with a single interface) makes them disagree: the\nsmall 'struct completion' stored by uea_probe() is then passed to\nusbatm_usb_disconnect(), which casts it to 'struct usbatm_data' and takes\ninstance->serialize, reading past the end of the allocation:\n\n  BUG: KASAN: slab-out-of-bounds in __mutex_lock+0x152a/0x1b80\n  Read of size 8 at addr ffff8880470e2c60 by task kworker/1:2/982\n  ...\n   __mutex_lock+0x152a/0x1b80\n   usbatm_usb_disconnect+0x70/0x820\n   uea_disconnect+0x133/0x2c0\n   usb_unbind_interface+0x1dd/0x9e0\n  ...\n  which belongs to the cache kmalloc-96 of size 96\n  The buggy address is located 0 bytes to the right of\n   allocated 96-byte region [ffff8880470e2c00, ffff8880470e2c60)\n\nReject such inconsistent descriptors in uea_probe() so that both handlers\nalways make the same pre/post-firmware decision."
    }
  ],
  "lastModified": "2026-08-19T17:20:44.223",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}