usb: gadget: configfs: fix out-of-bounds read of qw_sign

Summary

CVECVE-2026-93120
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-09-17 17:18:06 UTC
Updated2026-09-17 17:18:06 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: usb: gadget: configfs: fix out-of-bounds read of qw_sign os_desc_qw_sign_show() passes OS_STRING_QW_SIGN_LEN as the input length to utf16s_to_utf8s(), but that argument counts UTF-16 code units while OS_STRING_QW_SIGN_LEN (14) is the byte size of qw_sign[]. The array holds only OS_STRING_QW_SIGN_LEN / 2 (7) code units, so the conversion reads up to 7 units (14 bytes) past the end of qw_sign[] into the following members of struct gadget_info when the stored signature fills the array without a NUL terminator, exposing those bytes through the configfs attribute. The store path halves the count for its input bound but passes the full byte count as the utf8s_to_utf16s() output limit; use the destination code-unit count in both directions.

Risk And Classification

EPSS: 0.002100000 probability, percentile 0.115970000 (date 2026-09-18)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 76180d716f91f035d9c8639497cf5459b44e1a51 b895dbed8ac9e12a5ffa1a2165575a8469f8340d git Not specified
CNA Linux Linux affected 76180d716f91f035d9c8639497cf5459b44e1a51 9b45125501aad2dff7730970461b455b0e0658ee git Not specified
CNA Linux Linux affected 76180d716f91f035d9c8639497cf5459b44e1a51 f6da500b0f8106882598b6dec87fe37d653946cf git Not specified
CNA Linux Linux affected 76180d716f91f035d9c8639497cf5459b44e1a51 a28c486434634f6d1e120711d2b09f3eddea6c98 git Not specified
CNA Linux Linux affected 76180d716f91f035d9c8639497cf5459b44e1a51 7e94cb967778e074411940db4db97f22ed77560c git Not specified
CNA Linux Linux affected 76180d716f91f035d9c8639497cf5459b44e1a51 afbf39c0f2297c6abef6d670a82a2079b0836191 git Not specified
CNA Linux Linux affected 76180d716f91f035d9c8639497cf5459b44e1a51 36315a330e067f7773196940552feacb1debbef1 git Not specified
CNA Linux Linux affected 76180d716f91f035d9c8639497cf5459b44e1a51 f63edb54d8f738f9c21e2068c777ae1c097df6b7 git Not specified
CNA Linux Linux affected 4.13 Not specified
CNA Linux Linux unaffected 4.13 semver Not specified
CNA Linux Linux unaffected 5.10.270 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.221 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.188 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.157 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.110 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.52 6.18.* semver Not specified
CNA Linux Linux unaffected 7.2.6 7.2.* semver Not specified
CNA Linux Linux unaffected 7.3-rc1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/afbf39c0f2297c6abef6d670a82a2079b0836191 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/f6da500b0f8106882598b6dec87fe37d653946cf 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/7e94cb967778e074411940db4db97f22ed77560c 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/36315a330e067f7773196940552feacb1debbef1 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/9b45125501aad2dff7730970461b455b0e0658ee 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/f63edb54d8f738f9c21e2068c777ae1c097df6b7 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/b895dbed8ac9e12a5ffa1a2165575a8469f8340d 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/a28c486434634f6d1e120711d2b09f3eddea6c98 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report