Executive brief
A vulnerability in the Linux kernel's USB gadget driver could allow a privileged process to read sensitive information from the system's memory. This occurs when the system handles specific USB control messages, potentially exposing data that was previously stored in memory to a management program (like a mobile phone's connection daemon). While an exploit requires physical access or a compromised high-privilege service, it could lead to the leakage of cryptographic keys or other sensitive system data.
Technical details
An information disclosure vulnerability exists in the ffs_ep0_read() function within the Linux kernel's USB gadget framework (FunctionFS). The function allocates a buffer using kmalloc() based on the length specified in a USB Setup packet but fails to account for 'short' transfers where the actual received data is less than the requested length. When a short transfer occurs, copy_to_user() still copies the full requested length, resulting in uninitialized slab residue being leaked to the FunctionFS daemon. This vulnerability is reachable via the FunctionFS device node, typically owned by privileged daemons like adbd. The issue has been patched by ensuring only the actual number of received bytes (req->actual) are copied to userspace.
Affected products
- Linux Linux Kernel versions prior to 6.9.5, 6.6.33, 6.1.93, 5.15.161, 5.10.219, 5.4.278, 4.19.316
Timeline
- 2026-04-19: other: Patch submitted by Michael Bommarito
- 2026-06-09: patched: Patch committed to stable trees
- 2026-07-19: disclosed: CVE published
References
- https://git.kernel.org/stable/c/23c1f7deb9dd8447ecde749850676302aa1e2bd3
- https://git.kernel.org/stable/c/4e036c10e7f4df5d951c69cc3697bc8e209c6d02
- https://git.kernel.org/stable/c/607730a414773a7cbe3037a64a6c64e72689ff5e
- https://git.kernel.org/stable/c/88874a19b2b093bfaaa1c0090fa536c44da8c08b
- https://git.kernel.org/stable/c/90ccf5fb63243fae1b4b3200f3310500500ecf2e
- https://git.kernel.org/stable/c/af32dbb2ca0b3d09271ab718d13857a457fa16f2
- https://git.kernel.org/stable/c/e835bf9a055f71874065a40780ca5560b7df8b33