CVE-2026-43427
In the Linux kernel, the following vulnerability has been resolved: usb: class: cdc-wdm: fix reordering issue in read code path Quoting the bug report: Due to compiler optimization or CPU out-of-order execution, the desc->length update can be reordered before the memmove. If this happens, wdm_read() can see the new length and call copy_to_user() on uninitialized memory. This also violates LKMM data race rules [1]. Fix it by using WRITE_ONCE and memory barriers.
Schwachstellenklasse
In the Linux kernel, the following vulnerability has been resolved: usb: class: cdc-wdm: fix reordering issue in read code path Quoting the bug report: Due to compiler optimization or CPU out-of-order execution, the desc->length update can be reordered before the memmove. If this happens, wdm_read() can see the new length and call copy_to_user() on uninitialized memory. This also violates LKMM data race rules [1]. Fix it by using WRITE_ONCE and memory barriers.
Betroffene Produkte
- linux linux_kernel
Quellen
- https://git.kernel.org/stable/c/170e8daca24da6edb4be82ab01abf44e87af387b
- https://git.kernel.org/stable/c/276aef0fd2b92f41b920ac891c72cadeee957934
- https://git.kernel.org/stable/c/4ee3062bf2c9a722afef429826e8607eaf3fc6a0
- https://git.kernel.org/stable/c/638328ca9c17ae6511ad62198c57bae32ffa3c91
- https://git.kernel.org/stable/c/67ed312124bb1b61858778ac0b985b48961c862a
- https://git.kernel.org/stable/c/8df672bfe3ec2268c2636584202755898e547173
Finden Sie die Schwachstelle, bevor es ein Angreifer tut.
Melden Sie sich mit GitHub an und starten Sie Ihr erstes Audit in weniger als einer Minute. Für den kostenlosen Plan ist keine Kreditkarte nötig.