CVE-2026-63928
Description
In the Linux kernel, the following vulnerability has been resolved:
USB: serial: omninet: fix memory corruption with small endpoint
Make sure that the bulk-out buffers are at least as large as the
hardcoded transfer size to avoid user-controlled slab corruption should
a malicious device report a smaller endpoint max packet size than
expected.
Metadata
Severity & Metrics
No CVSS data available.
Affected products (2)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Linux | Linux | — | 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 180996f0ca774001944e4afa452d569ba2f6455c, 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < b496e25ead5976bce2891dacaed09beb53a54f9f, 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 4e7d32189d6219beb7db37cd0ea36b6bac7dfedb, 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 9a3860454bdfb765f936965e975c594352602ffc … |
| Linux | Linux | — | 2.6.12, 0 < 2.6.12, 5.10.259 ≤ 5.10.*, 5.15.210 ≤ 5.15.* … |
References (8)
- https://git.kernel.org/stable/c/180996f0ca774001944e4afa452d569ba2f6455c
- https://git.kernel.org/stable/c/b496e25ead5976bce2891dacaed09beb53a54f9f
- https://git.kernel.org/stable/c/4e7d32189d6219beb7db37cd0ea36b6bac7dfedb
- https://git.kernel.org/stable/c/9a3860454bdfb765f936965e975c594352602ffc
- https://git.kernel.org/stable/c/0bda1893e4cc4ad2b7dcdbaca246f2af688c6c2a
- https://git.kernel.org/stable/c/0fee0ccac29e088d4bfab7e2d075725dcecd803d
- https://git.kernel.org/stable/c/f34cf2928387fba01a78381f3258c7e1428897d9
- https://git.kernel.org/stable/c/60df93d30f9bdd27db17c4d80ed80ef718d7226b