SB20260812157 - Out-of-bounds read in Linux kernel gadget function driver
Published: August 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-68366)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in uvc_send_response() when processing a UVCIOC_SEND_RESPONSE ioctl with a crafted response length. A local user can supply a crafted struct uvc_request_data to cause an out-of-bounds read and disclose sensitive information.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1f03658f3e9b2f8fd1d1003ba389a0390b49a350
- https://git.kernel.org/stable/c/4e116372b7a4f87df0dc0ed4b0ab5b0bb0cc5796
- https://git.kernel.org/stable/c/662f6c6c6ff8a6c508e1646c09cae74e28f3cca6
- https://git.kernel.org/stable/c/b70dc75e85ba968b7b76eebfe5d63000080b875b
- https://git.kernel.org/stable/c/c8510fbbea09ef0170b56b14dc2b5890dc75be07