Out-of-bounds read in Linux kernel - CVE-2026-68088
Published: August 13, 2026
Vulnerability identifier: #VU142237
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-68088
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in rndis_query_response() in the RNDIS USB gadget function when processing a crafted RNDIS query message. A remote attacker can send a specially crafted RNDIS query message to cause a denial of service.
Affected software
Linux kernel
Ubuntu
linux (Ubuntu package)
linux-gcp-7.0 (Ubuntu package)
linux-oem-7.0 (Ubuntu package)
Ubuntu
linux (Ubuntu package)
linux-gcp-7.0 (Ubuntu package)
linux-oem-7.0 (Ubuntu package)
How to mitigate CVE-2026-68088
Install security update from vendor's repository.
Linux kernel - update to 7.0 rc3
linux (Ubuntu package) - addressed in versions 7.0.0-31.31, 7.0.0-31.31.1, 7.0.0-31.31~24.04.1, 7.0.0-1006.7, 7.0.0-1011.11~24.04.1, 7.0.0-1012.12, 7.0.0-1012.12~24.04.1
linux-gcp-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-oem-7.0 (Ubuntu package) - update to 7.0.0-1013.13
linux (Ubuntu package) - addressed in versions 7.0.0-31.31, 7.0.0-31.31.1, 7.0.0-31.31~24.04.1, 7.0.0-1006.7, 7.0.0-1011.11~24.04.1, 7.0.0-1012.12, 7.0.0-1012.12~24.04.1
linux-gcp-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-oem-7.0 (Ubuntu package) - update to 7.0.0-1013.13
External References
- https://git.kernel.org/stable/c/585921866d2d7d65d4b0d89927c78f784668cf5f
- https://git.kernel.org/stable/c/95f90eea070837f7c72207d5520f805bdefc3bc5
- https://git.kernel.org/stable/c/b09716040f3fa4a252eeda3ceb5295ea0e39c1fb
- https://git.kernel.org/stable/c/bb2b4402b4571b0c989b977779f7be01107ca425
- https://git.kernel.org/stable/c/caea8b120604312bab2bfeb1a972f9cd17019e93
- https://git.kernel.org/stable/c/e01e7814b4223560eab0513b7c15b8c82bdc83f3
- https://git.kernel.org/stable/c/efcf4e4eeea0d69d8da72a7bc5cbd49b6192260e
- https://git.kernel.org/stable/c/f5870777458d8be65d7cd08bc750a03f17998350