« Volver al listado

CVE-2026-68366

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer

uvc_send_response() builds the UVC control response from a user-supplied struct uvc_request_data:

req->length is clamped to uvc->event_length, which is taken from the host control request wLength (up to UVC_MAX_REQUEST_SIZE, 64), and to data->length, which comes from the UVCIOC_SEND_RESPONSE ioctl and is only checked for being negative. The source buffer data->data is only 60 bytes, so a response with uvc->event_length and data->length both greater than 60 makes memcpy() read past the end of data->data.

Leer descripción completaMostrar menos

Clamp req->length to sizeof(data->data) as well.

Detalles técnicos trazas, registros y código del informe original
	req->length = min_t(unsigned int, uvc->event_length, data->length);
	...
	memcpy(req->buf, data->data, req->length);

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-68366",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1",
              "lessThan": "eaf783c005299a702f2cc96b08cd21ede081f098",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1",
              "lessThan": "568e68d8f80395a64848aa2946af8ade72da0ffb",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1",
              "lessThan": "82ec2c1e456b17451f0736c3983402642f961733",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1",
              "lessThan": "4e116372b7a4f87df0dc0ed4b0ab5b0bb0cc5796",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1",
              "lessThan": "662f6c6c6ff8a6c508e1646c09cae74e28f3cca6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1",
              "lessThan": "1f03658f3e9b2f8fd1d1003ba389a0390b49a350",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1",
              "lessThan": "c8510fbbea09ef0170b56b14dc2b5890dc75be07",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a5eaaa1f33e771fa1651a4a7652b8a5f9fa7f6c1",
              "lessThan": "b70dc75e85ba968b7b76eebfe5d63000080b875b",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/usb/gadget/function/uvc_v4l2.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.10"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.10",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.265",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.216",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.183",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.148",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.101",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.42",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/usb/gadget/function/uvc_v4l2.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-10T13:20:29.230",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/1f03658f3e9b2f8fd1d1003ba389a0390b49a350",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4e116372b7a4f87df0dc0ed4b0ab5b0bb0cc5796",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/568e68d8f80395a64848aa2946af8ade72da0ffb",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/662f6c6c6ff8a6c508e1646c09cae74e28f3cca6",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/82ec2c1e456b17451f0736c3983402642f961733",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b70dc75e85ba968b7b76eebfe5d63000080b875b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c8510fbbea09ef0170b56b14dc2b5890dc75be07",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/eaf783c005299a702f2cc96b08cd21ede081f098",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer\n\nuvc_send_response() builds the UVC control response from a user-supplied\nstruct uvc_request_data:\n\n\treq->length = min_t(unsigned int, uvc->event_length, data->length);\n\t...\n\tmemcpy(req->buf, data->data, req->length);\n\nreq->length is clamped to uvc->event_length, which is taken from the\nhost control request wLength (up to UVC_MAX_REQUEST_SIZE, 64), and to\ndata->length, which comes from the UVCIOC_SEND_RESPONSE ioctl and is\nonly checked for being negative.  The source buffer data->data is only\n60 bytes, so a response with uvc->event_length and data->length both\ngreater than 60 makes memcpy() read past the end of data->data.\n\nClamp req->length to sizeof(data->data) as well."
    }
  ],
  "lastModified": "2026-08-19T17:20:46.203",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}