HomeDefectsLIN1025-16926
Acknowledged

LIN1025-16926 : Security Advisory - linux - CVE-2026-63896

Created: Aug 1, 2026    Updated: Aug 11, 2026
Found In Version: 10.25.33.2
Severity: Standard
Applicable for: Wind River Linux LTS 25
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:  usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling  The WebUSB GET_URL handler in composite_setup() narrows landing_page_length to fit the host-supplied wLength using  	landing_page_length = w_length 		- WEBUSB_URL_DESCRIPTOR_HEADER_LENGTH + landing_page_offset;  If wLength is smaller than WEBUSB_URL_DESCRIPTOR_HEADER_LENGTH the unsigned subtraction wraps, and the subsequent  	memcpy(url_descriptor->URL, 	       cdev->landing_page + landing_page_offset, 	       landing_page_length - landing_page_offset);  ends up copying close to UINT_MAX bytes from cdev->landing_page into cdev->req->buf.  KASAN reports a slab-out-of-bounds in composite_setup on the kmalloc-2k gadget_info allocation, and FORTIFY_SOURCE traps the memcpy as a 4294967293-byte field-spanning write into url_descriptor->URL (size 252).  A USB host can reach this from a single SETUP packet against any gadget that has webusb/use=1 and a landingPage configured.  Handle the small-wLength case before the math: when the host requested fewer bytes than the URL descriptor header, only the header is meaningful and no URL bytes need to be copied.  Setting landing_page_length to landing_page_offset makes the existing memcpy a no-op and leaves the descriptor returned to the host unchanged for all larger wLength values.