« Volver al listado

CVE-2026-93120

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: configfs: fix out-of-bounds read of qw_sign

os_desc_qw_sign_show() passes OS_STRING_QW_SIGN_LEN as the input length to utf16s_to_utf8s(), but that argument counts UTF-16 code units while OS_STRING_QW_SIGN_LEN (14) is the byte size of qw_sign[]. The array holds only OS_STRING_QW_SIGN_LEN / 2 (7) code units, so the conversion reads up to 7 units (14 bytes) past the end of qw_sign[] into the following members of struct gadget_info when the stored signature fills the array without a NUL terminator, exposing those bytes through the configfs attribute.

Leer descripción completaMostrar menos

The store path halves the count for its input bound but passes the full byte count as the utf8s_to_utf16s() output limit; use the destination code-unit count in both directions.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-93120",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "76180d716f91f035d9c8639497cf5459b44e1a51",
              "lessThan": "b895dbed8ac9e12a5ffa1a2165575a8469f8340d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "76180d716f91f035d9c8639497cf5459b44e1a51",
              "lessThan": "9b45125501aad2dff7730970461b455b0e0658ee",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "76180d716f91f035d9c8639497cf5459b44e1a51",
              "lessThan": "f6da500b0f8106882598b6dec87fe37d653946cf",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "76180d716f91f035d9c8639497cf5459b44e1a51",
              "lessThan": "a28c486434634f6d1e120711d2b09f3eddea6c98",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "76180d716f91f035d9c8639497cf5459b44e1a51",
              "lessThan": "7e94cb967778e074411940db4db97f22ed77560c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "76180d716f91f035d9c8639497cf5459b44e1a51",
              "lessThan": "afbf39c0f2297c6abef6d670a82a2079b0836191",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "76180d716f91f035d9c8639497cf5459b44e1a51",
              "lessThan": "36315a330e067f7773196940552feacb1debbef1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "76180d716f91f035d9c8639497cf5459b44e1a51",
              "lessThan": "f63edb54d8f738f9c21e2068c777ae1c097df6b7",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/usb/gadget/configfs.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.13"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.13",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.270",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.221",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/usb/gadget/configfs.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:18:06.667",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/36315a330e067f7773196940552feacb1debbef1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7e94cb967778e074411940db4db97f22ed77560c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9b45125501aad2dff7730970461b455b0e0658ee",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a28c486434634f6d1e120711d2b09f3eddea6c98",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/afbf39c0f2297c6abef6d670a82a2079b0836191",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b895dbed8ac9e12a5ffa1a2165575a8469f8340d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f63edb54d8f738f9c21e2068c777ae1c097df6b7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f6da500b0f8106882598b6dec87fe37d653946cf",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: configfs: fix out-of-bounds read of qw_sign\n\nos_desc_qw_sign_show() passes OS_STRING_QW_SIGN_LEN as the input\nlength to utf16s_to_utf8s(), but that argument counts UTF-16 code\nunits while OS_STRING_QW_SIGN_LEN (14) is the byte size of qw_sign[].\nThe array holds only OS_STRING_QW_SIGN_LEN / 2 (7) code units, so the\nconversion reads up to 7 units (14 bytes) past the end of qw_sign[]\ninto the following members of struct gadget_info when the stored\nsignature fills the array without a NUL terminator, exposing those\nbytes through the configfs attribute.\n\nThe store path halves the count for its input bound but passes the\nfull byte count as the utf8s_to_utf16s() output limit; use the\ndestination code-unit count in both directions."
    }
  ],
  "lastModified": "2026-09-17T17:18:06.667",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}