SB20260919154 - Reliance on undefined behavior in Linux kernel usb atm driver
Published: September 19, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Reliance on undefined behavior (CVE-ID: CVE-2026-90055)
CWE-ID: CWE-758 - Reliance on Undefined, Unspecified, or Implementation-Defined Behavior
CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger undefined behavior.
The vulnerability exists due to improper initialization of ci_range bit counts in usbatm_atm_init() when processing ATM PVC bind requests. A remote attacker can bind an ATM PVC to trigger undefined behavior.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1e964d414bfd9f8dfe9948d08e4b9dda4ed2e422
- https://git.kernel.org/stable/c/561cbd6d49022c9a383e22a39c87a165a4d39f9c
- https://git.kernel.org/stable/c/75667703115154a4fd9cf259d4f826d8729cbcda
- https://git.kernel.org/stable/c/76bc7c3a44856744b64aa91d9afe6d9522a78c42
- https://git.kernel.org/stable/c/7baa0c92be39eb3da755ed6f200497a57078c47b
- https://git.kernel.org/stable/c/8442586526c406527bf31206e538c0ce6bc672e6
- https://git.kernel.org/stable/c/a60fd8c6dbaa76da4163cf225ed2b9e982540f39
- https://git.kernel.org/stable/c/ff7f77a234f7b74e5955a6e34fa74eca4c9ca44c