CVE-2026-68344
Last modified
CVE-2026-68344 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect uea_probe() distinguishes a pre-firmware device from a post-firmware one using the USB id (UEA_IS_PREFIRM()), and stores a different object as the interface data in each case: a 'struct completion' for a pre-firmware device (to be waited on in .disconnect()), or a 'struct usbatm_data' for a post-firmware one. uea_disconnect() instead tells the two apart by the number of interfaces of the active configuration (a pre-firmware device exposes a single interface, ADI930 has 2 and eagle has 3), and casts the interface data accordingly. Because the two handlers use different criteria, a crafted device that advertises a pre-firmware id together with a multi-interface descriptor (or a post-firmware id with a single interface) makes them disagree: the small 'struct completion' stored by uea_probe() is then passed to usbatm_usb_disconnect(), which casts it to 'struct usbatm_data' and takes instance->serialize, reading past the end of the allocation: BUG: KASAN: slab-out-of-bounds in __mutex_lock+0x152a/0x1b80 Read of size 8 at addr ffff8880470e2c60 by task kworker/1:2/982 ... __mutex_lock+0x152a/0x1b80 usbatm_usb_disconnect+0x70/0x820 uea_disconnect+0x133/0x2c0 usb_unbind_interface+0x1dd/0x9e0 ... which belongs to the cache kmalloc-96 of size 96 The buggy address is located 0 bytes to the right of allocated 96-byte region [ffff8880470e2c00, ffff8880470e2c60) Reject such inconsistent descriptors in uea_probe() so that both handlers always make the same pre/post-firmware decision..
Description
In the Linux kernel, the following vulnerability has been resolved: usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect uea_probe() distinguishes a pre-firmware device from a post-firmware one using the USB id (UEA_IS_PREFIRM()), and stores a different object as the interface data in each case: a 'struct completion' for a pre-firmware device (to be waited on in .disconnect()), or a 'struct usbatm_data' for a post-firmware one. uea_disconnect() instead tells the two apart by the number of interfaces of the active configuration (a pre-firmware device exposes a single interface, ADI930 has 2 and eagle has 3), and casts the interface data accordingly. Because the two handlers use different criteria, a crafted device that advertises a pre-firmware id together with a multi-interface descriptor (or a post-firmware id with a single interface) makes them disagree: the small 'struct completion' stored by uea_probe() is then passed to usbatm_usb_disconnect(), which casts it to 'struct usbatm_data' and takes instance->serialize, reading past the end of the allocation: BUG: KASAN: slab-out-of-bounds in __mutex_lock+0x152a/0x1b80 Read of size 8 at addr ffff8880470e2c60 by task kworker/1:2/982 ... __mutex_lock+0x152a/0x1b80 usbatm_usb_disconnect+0x70/0x820 uea_disconnect+0x133/0x2c0 usb_unbind_interface+0x1dd/0x9e0 ... which belongs to the cache kmalloc-96 of size 96 The buggy address is located 0 bytes to the right of allocated 96-byte region [ffff8880470e2c00, ffff8880470e2c60) Reject such inconsistent descriptors in uea_probe() so that both handlers always make the same pre/post-firmware decision.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= f2a6abc670104fc3e383ee3b1cf35c070485e3df, < c035b1198906dd5bd3df9a3045b59254bad1ea7a; >= c581e30ae5b332d8acef64475a211b3f82099941, < 9904a46401198872ab3de34fd11f383831ef3428; >= 509b51327320bdeaef1969248177a446ded073ab, < d0a57f19fe2865b9747484f5f9c631f944ed9a0f; >= ddcdac47e1f2651c7be60e299f98faf981522797, < 0cc0c4c14150bb5a16b88dd61368f96cd4caa9ce; >= e2674dfbed8a30d57e2bc872c4bfa6c3eec918bf, < 71132cedd1ecbc4032d76e9928c18a10f7e39b80; d85f19aaef42a03e3e4765d659c761c8750a7f23; 76861031b43a18065d13f9ffb8595d25c7576005; bbfedc84714064ea4845e6b76f96316eb5bb65d8; >= 6.6.145, < 6.6.148; >= 6.12.97, < 6.12.101; >= 6.18.40, < 6.18.42; >= 7.1.5, < 7.1.6; >= 5.10.261, < 5.11; >= 5.15.212, < 5.16; >= 6.1.178, < 6.2 |
| Linux | Linux | 7.2-rc3 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-68344?
How severe is CVE-2026-68344?
How do I fix CVE-2026-68344?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-68339In the Linux kernel, the following vulnerability has been re…
- CVE-2026-6834The a+HRD developed by aEnrich has a Missing Authorization v…7.1
- CVE-2026-68340In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68341In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68342In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68343In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68345In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68346In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68347In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68348In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68349In the Linux kernel, the following vulnerability has been re…
- CVE-2026-6835The a+HCM developed by aEnrich has an Arbitrary File Upload …6.1
Are you affected by CVE-2026-68344?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
