Description
In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: configfs: fix out-of-bounds read of qw_sign

os_desc_qw_sign_show() passes OS_STRING_QW_SIGN_LEN as the input
length to utf16s_to_utf8s(), but that argument counts UTF-16 code
units while OS_STRING_QW_SIGN_LEN (14) is the byte size of qw_sign[].
The array holds only OS_STRING_QW_SIGN_LEN / 2 (7) code units, so the
conversion reads up to 7 units (14 bytes) past the end of qw_sign[]
into the following members of struct gadget_info when the stored
signature fills the array without a NUL terminator, exposing those
bytes through the configfs attribute.

The store path halves the count for its input bound but passes the
full byte count as the utf8s_to_utf16s() output limit; use the
destination code-unit count in both directions.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

This vulnerability occurs when the kernel's USB gadget configfs subsystem reads beyond the end of the qw_sign field due to a mismatch between the byte count and the code‑unit count used in the conversion routines. The bug allows an attacker who can read the configfs attribute to retrieve bytes that belong to adjacent members of the gadget_info structure, potentially exposing kernel data that should be private. The underlying weakness is an out‑of‑bounds read, classified as CWE‑119, and can result in information exposure (CWE‑200).

Affected Systems

The issue is present in the Linux kernel wherever the usb: gadget: configfs subsystem is enabled. The exact kernel versions before the changes introduced in the referenced commits are not enumerated, but any kernel derived from the revision preceding commit 36315a330e067f7773196940552feacb1debbef1 is affected.

Risk and Exploitability

The CVSS score is not reported, but the EPSS score is below 1 %, indicating a very low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the attacker to have access to the configfs USB gadget attribute, which is normally restricted to privileged users or root. Therefore, while the data exposure could be significant if exploited, the overall risk for most deployments remains modest.

Generated by OpenCVE AI on September 19, 2026 at 07:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes commit 36315a330e067f7773196940552feacb1debbef1 or subsequent versions that contain the fix for the usb gadget configfs out-of-bounds read.
  • If a timely kernel update is not possible, restrict access to the configfs USB gadget paths (/sys/kernel/config/.../usb_gadget) to only privileged users, or remount configfs with "mode=0555" or remove the usb gadget modules from exposed devices.
  • Enable kernel hardening options such as CONFIG_STRICT_DEVMEM and grsecurity's no kernel stack leak features to reduce the window for memory disclosure, and use SELinux or AppArmor policies to contain gadget attributes.
  • Check for device‑specific patches from vendors that customize the Linux kernel; some embedded or OEM kernels may include the patch or similar fixes.

Generated by OpenCVE AI on September 19, 2026 at 07:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-200

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: usb: gadget: configfs: fix out-of-bounds read of qw_sign os_desc_qw_sign_show() passes OS_STRING_QW_SIGN_LEN as the input length to utf16s_to_utf8s(), but that argument counts UTF-16 code units while OS_STRING_QW_SIGN_LEN (14) is the byte size of qw_sign[]. The array holds only OS_STRING_QW_SIGN_LEN / 2 (7) code units, so the conversion reads up to 7 units (14 bytes) past the end of qw_sign[] into the following members of struct gadget_info when the stored signature fills the array without a NUL terminator, exposing those bytes through the configfs attribute. The store path halves the count for its input bound but passes the full byte count as the utf8s_to_utf16s() output limit; use the destination code-unit count in both directions.
Title usb: gadget: configfs: fix out-of-bounds read of qw_sign
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:26.548Z

Reserved: 2026-09-17T16:02:15.086Z

Link: CVE-2026-93120

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:06.667

Modified: 2026-09-17T17:18:06.667

Link: CVE-2026-93120

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T15:45:16Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor