CVE-2026-93120
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: configfs: fix out-of-bounds read of qw_sign
os_desc_qw_sign_show() passes OS_STRING_QW_SIGN_LEN as the input length to utf16s_to_utf8s(), but that argument counts UTF-16 code units while OS_STRING_QW_SIGN_LEN (14) is the byte size of qw_sign[]. The array holds only OS_STRING_QW_SIGN_LEN / 2 (7) code units, so the conversion reads up to 7 units (14 bytes) past the end of qw_sign[] into the following members of struct gadget_info when the stored signature fills the array without a NUL terminator, exposing those bytes through the configfs attribute.
Leer descripción completaMostrar menos
The store path halves the count for its input bound but passes the full byte count as the utf8s_to_utf16s() output limit; use the destination code-unit count in both directions.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/36315a330e067f7773196940552feacb1debbef1
- https://git.kernel.org/stable/c/7e94cb967778e074411940db4db97f22ed77560c
- https://git.kernel.org/stable/c/9b45125501aad2dff7730970461b455b0e0658ee
- https://git.kernel.org/stable/c/a28c486434634f6d1e120711d2b09f3eddea6c98
- https://git.kernel.org/stable/c/afbf39c0f2297c6abef6d670a82a2079b0836191
- https://git.kernel.org/stable/c/b895dbed8ac9e12a5ffa1a2165575a8469f8340d
- https://git.kernel.org/stable/c/f63edb54d8f738f9c21e2068c777ae1c097df6b7
- https://git.kernel.org/stable/c/f6da500b0f8106882598b6dec87fe37d653946cf
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-93120",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "76180d716f91f035d9c8639497cf5459b44e1a51",
"lessThan": "b895dbed8ac9e12a5ffa1a2165575a8469f8340d",
"versionType": "git"
},
{
"status": "affected",
"version": "76180d716f91f035d9c8639497cf5459b44e1a51",
"lessThan": "9b45125501aad2dff7730970461b455b0e0658ee",
"versionType": "git"
},
{
"status": "affected",
"version": "76180d716f91f035d9c8639497cf5459b44e1a51",
"lessThan": "f6da500b0f8106882598b6dec87fe37d653946cf",
"versionType": "git"
},
{
"status": "affected",
"version": "76180d716f91f035d9c8639497cf5459b44e1a51",
"lessThan": "a28c486434634f6d1e120711d2b09f3eddea6c98",
"versionType": "git"
},
{
"status": "affected",
"version": "76180d716f91f035d9c8639497cf5459b44e1a51",
"lessThan": "7e94cb967778e074411940db4db97f22ed77560c",
"versionType": "git"
},
{
"status": "affected",
"version": "76180d716f91f035d9c8639497cf5459b44e1a51",
"lessThan": "afbf39c0f2297c6abef6d670a82a2079b0836191",
"versionType": "git"
},
{
"status": "affected",
"version": "76180d716f91f035d9c8639497cf5459b44e1a51",
"lessThan": "36315a330e067f7773196940552feacb1debbef1",
"versionType": "git"
},
{
"status": "affected",
"version": "76180d716f91f035d9c8639497cf5459b44e1a51",
"lessThan": "f63edb54d8f738f9c21e2068c777ae1c097df6b7",
"versionType": "git"
}
],
"programFiles": [
"drivers/usb/gadget/configfs.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.13"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.13",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.270",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.221",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.188",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.157",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.110",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.52",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.6",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/usb/gadget/configfs.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-17T17:18:06.667",
"references": [
{
"url": "https://git.kernel.org/stable/c/36315a330e067f7773196940552feacb1debbef1",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7e94cb967778e074411940db4db97f22ed77560c",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/9b45125501aad2dff7730970461b455b0e0658ee",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a28c486434634f6d1e120711d2b09f3eddea6c98",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/afbf39c0f2297c6abef6d670a82a2079b0836191",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/b895dbed8ac9e12a5ffa1a2165575a8469f8340d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f63edb54d8f738f9c21e2068c777ae1c097df6b7",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f6da500b0f8106882598b6dec87fe37d653946cf",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: configfs: fix out-of-bounds read of qw_sign\n\nos_desc_qw_sign_show() passes OS_STRING_QW_SIGN_LEN as the input\nlength to utf16s_to_utf8s(), but that argument counts UTF-16 code\nunits while OS_STRING_QW_SIGN_LEN (14) is the byte size of qw_sign[].\nThe array holds only OS_STRING_QW_SIGN_LEN / 2 (7) code units, so the\nconversion reads up to 7 units (14 bytes) past the end of qw_sign[]\ninto the following members of struct gadget_info when the stored\nsignature fills the array without a NUL terminator, exposing those\nbytes through the configfs attribute.\n\nThe store path halves the count for its input bound but passes the\nfull byte count as the utf8s_to_utf16s() output limit; use the\ndestination code-unit count in both directions."
}
],
"lastModified": "2026-09-17T17:18:06.667",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}