usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect
Summary
| CVE | CVE-2026-68344 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-10 13:20:24 UTC |
| Updated | 2026-08-10 13:20:24 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect
uea_probe() distinguishes a pre-firmware device from a post-firmware one
using the USB id (UEA_IS_PREFIRM()), and stores a different object as the
interface data in each case: a 'struct completion' for a pre-firmware
device (to be waited on in .disconnect()), or a 'struct usbatm_data' for a
post-firmware one.
uea_disconnect() instead tells the two apart by the number of interfaces
of the active configuration (a pre-firmware device exposes a single
interface, ADI930 has 2 and eagle has 3), and casts the interface data
accordingly.
Because the two handlers use different criteria, a crafted device that
advertises a pre-firmware id together with a multi-interface descriptor
(or a post-firmware id with a single interface) makes them disagree: the
small 'struct completion' stored by uea_probe() is then passed to
usbatm_usb_disconnect(), which casts it to 'struct usbatm_data' and takes
instance->serialize, reading past the end of the allocation:
BUG: KASAN: slab-out-of-bounds in __mutex_lock+0x152a/0x1b80
Read of size 8 at addr ffff8880470e2c60 by task kworker/1:2/982
...
__mutex_lock+0x152a/0x1b80
usbatm_usb_disconnect+0x70/0x820
uea_disconnect+0x133/0x2c0
usb_unbind_interface+0x1dd/0x9e0
...
which belongs to the cache kmalloc-96 of size 96
The buggy address is located 0 bytes to the right of
allocated 96-byte region [ffff8880470e2c00, ffff8880470e2c60)
Reject such inconsistent descriptors in uea_probe() so that both handlers
always make the same pre/post-firmware decision. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected f2a6abc670104fc3e383ee3b1cf35c070485e3df c035b1198906dd5bd3df9a3045b59254bad1ea7a git |
Not specified |
| CNA |
Linux |
Linux |
affected c581e30ae5b332d8acef64475a211b3f82099941 9904a46401198872ab3de34fd11f383831ef3428 git |
Not specified |
| CNA |
Linux |
Linux |
affected 509b51327320bdeaef1969248177a446ded073ab d0a57f19fe2865b9747484f5f9c631f944ed9a0f git |
Not specified |
| CNA |
Linux |
Linux |
affected ddcdac47e1f2651c7be60e299f98faf981522797 0cc0c4c14150bb5a16b88dd61368f96cd4caa9ce git |
Not specified |
| CNA |
Linux |
Linux |
affected e2674dfbed8a30d57e2bc872c4bfa6c3eec918bf 71132cedd1ecbc4032d76e9928c18a10f7e39b80 git |
Not specified |
| CNA |
Linux |
Linux |
affected d85f19aaef42a03e3e4765d659c761c8750a7f23 git |
Not specified |
| CNA |
Linux |
Linux |
affected 76861031b43a18065d13f9ffb8595d25c7576005 git |
Not specified |
| CNA |
Linux |
Linux |
affected bbfedc84714064ea4845e6b76f96316eb5bb65d8 git |
Not specified |
| CNA |
Linux |
Linux |
affected 6.6.145 6.6.148 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 6.12.97 6.12.101 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 6.18.40 6.18.42 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 7.1.5 7.1.6 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 5.10.261 5.11 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 5.15.212 5.16 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 6.1.178 6.2 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 7.2-rc3 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2-rc3 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.148 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.101 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.42 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1.6 7.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2-rc5 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/9904a46401198872ab3de34fd11f383831ef3428 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/d0a57f19fe2865b9747484f5f9c631f944ed9a0f |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/71132cedd1ecbc4032d76e9928c18a10f7e39b80 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/c035b1198906dd5bd3df9a3045b59254bad1ea7a |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/0cc0c4c14150bb5a16b88dd61368f96cd4caa9ce |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.