Input: xpad - fix out-of-bounds access for Share button

Summary

CVECVE-2026-63943
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-07-19 16:17:12 UTC
Updated2026-07-19 16:17:12 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: Input: xpad - fix out-of-bounds access for Share button xpadone_process_packet() receives len directly from urb->actual_length and uses it to index the share-button byte at data[len - 18] or data[len - 26]. Since both len and data[0] are under the device's control, a broken controller can send a GIP_CMD_INPUT packet with actual_length < 18 (e.g. 5 bytes) and reach this code path, causing accesses beyond the actual array. Fix this by calculating the offset and checking bounds against the packet length.

Risk And Classification

EPSS: 0.002000000 probability, percentile 0.100210000 (date 2026-07-20)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected cbc82e7db16d59c301457312a624a7de2c03cd4a bcfb4833cd4078a1a356ef451838b75cd233099e git Not specified
CNA Linux Linux affected 302a0cd0bbc450998429a3f4267970a4b93251a8 37ec54abfdd63a63fd50734a9c4e4cbc1e5795af git Not specified
CNA Linux Linux affected 4ef46367073b107ec22f46fe5f12176e87c238e8 9749db57233b396353ad5dee81eec9d9880c9246 git Not specified
CNA Linux Linux affected 4ef46367073b107ec22f46fe5f12176e87c238e8 6346b0895b574ce45f3747b9c508c72f70e6abef git Not specified
CNA Linux Linux affected 4ef46367073b107ec22f46fe5f12176e87c238e8 6cdc46b38cf146ce81d4831b6472dbf7731849a2 git Not specified
CNA Linux Linux affected a7e3ddd1d9a3d0b26465ed01d464e3c05479ebc8 git Not specified
CNA Linux Linux affected 6.6.91 6.6.143 semver Not specified
CNA Linux Linux affected 6.12.29 6.12.93 semver Not specified
CNA Linux Linux affected 6.14.7 6.15 semver Not specified
CNA Linux Linux affected 6.15 Not specified
CNA Linux Linux unaffected 6.15 semver Not specified
CNA Linux Linux unaffected 6.6.143 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.93 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.35 6.18.* semver Not specified
CNA Linux Linux unaffected 7.0.12 7.0.* semver Not specified
CNA Linux Linux unaffected 7.1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/6346b0895b574ce45f3747b9c508c72f70e6abef 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/6cdc46b38cf146ce81d4831b6472dbf7731849a2 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/9749db57233b396353ad5dee81eec9d9880c9246 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/37ec54abfdd63a63fd50734a9c4e4cbc1e5795af 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/bcfb4833cd4078a1a356ef451838b75cd233099e 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report