HomeDefectsLIN1022-25032
Acknowledged

LIN1022-25032 : Security Advisory - linux - CVE-2026-31720

Created: May 12, 2026    Updated: May 14, 2026
Found In Version: 10.22.33.2
Severity: Standard
Applicable for: Wind River Linux LTS 22
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:  usb: gadget: f_uac1_legacy: validate control request size  f_audio_complete() copies req->length bytes into a 4-byte stack variable:    u32 data = 0;   memcpy(&data, req->buf, req->length);  req->length is derived from the host-controlled USB request path, which can lead to a stack out-of-bounds write.  Validate req->actual against the expected payload size for the supported control selectors and decode only the expected amount of data.  This avoids copying a host-influenced length into a fixed-size stack object.