CVE-2026-68088

UnknownEPSS 0.18%

Last modified

CVE-2026-68088 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: usb: gadget: function: rndis: add length check to response query Add variable representations for BufLength and BufOffset in rndis_query_response(), and perform a length check on them. This is identical to how rndis_set_response() handles these parameters.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: function: rndis: add length check to response query Add variable representations for BufLength and BufOffset in rndis_query_response(), and perform a length check on them. This is identical to how rndis_set_response() handles these parameters.

Metrics

EPSS Probability
0.18%

7.5th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 340600ab4cf0cc41efd01a65af97ebb7d35a7f85, < efcf4e4eeea0d69d8da72a7bc5cbd49b6192260e; >= 340600ab4cf0cc41efd01a65af97ebb7d35a7f85, < bb2b4402b4571b0c989b977779f7be01107ca425; >= 340600ab4cf0cc41efd01a65af97ebb7d35a7f85, < 585921866d2d7d65d4b0d89927c78f784668cf5f; >= 340600ab4cf0cc41efd01a65af97ebb7d35a7f85, < caea8b120604312bab2bfeb1a972f9cd17019e93; >= 340600ab4cf0cc41efd01a65af97ebb7d35a7f85, < f5870777458d8be65d7cd08bc750a03f17998350; >= 340600ab4cf0cc41efd01a65af97ebb7d35a7f85, < e01e7814b4223560eab0513b7c15b8c82bdc83f3; >= 340600ab4cf0cc41efd01a65af97ebb7d35a7f85, < b09716040f3fa4a252eeda3ceb5295ea0e39c1fb; >= 340600ab4cf0cc41efd01a65af97ebb7d35a7f85, < 95f90eea070837f7c72207d5520f805bdefc3bc5
LinuxLinux2.6.13

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-68088?
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: function: rndis: add length check to response query Add variable representations for BufLength and BufOffset in rndis_query_response(), and perform a length check on them. This is identical to how rndis_set_response() handles these parameters.
How severe is CVE-2026-68088?
Severity scoring for CVE-2026-68088 is pending analysis. The EPSS model estimates a 0.18% probability of exploitation in the next 30 days.
How do I fix CVE-2026-68088?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-68088?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST