Executive brief
A vulnerability exists in the Linux kernel's USB gadget subsystem when handling WebUSB requests. An attacker with physical access or control over a connected USB host can trigger a system crash or memory corruption by sending a specially crafted request. This affects devices configured to use WebUSB with a landing page, potentially impacting the stability and security of embedded Linux systems.
Technical details
An integer underflow vulnerability exists in `drivers/usb/gadget/composite.c` within the `composite_setup()` function. When handling a WebUSB `GET_URL` request, the code fails to validate that the host-supplied `wLength` is greater than the `WEBUSB_URL_DESCRIPTOR_HEADER_LENGTH`. If `wLength` is smaller, an unsigned subtraction wraps around to a very large value, causing `memcpy()` to attempt to copy nearly 4GB of data. This results in a slab-out-of-bounds access and a kernel panic or memory corruption. The vulnerability is reachable via a single USB SETUP packet on gadgets with WebUSB enabled and a landing page configured. Patches have been released for various stable kernel branches.
Affected products
- Linux Linux Kernel 6.3 to 6.9.x
Timeline
- 2026-05-12: other: Vulnerability fixed in source code
- 2026-07-19: disclosed: CVE-2026-63896 published
References
- https://git.kernel.org/stable/c/046870ff6b6f7b743c953c061043a9b30700d491
- https://git.kernel.org/stable/c/6c5dbc104dadd79fc2923497c20bae759a18758c
- https://git.kernel.org/stable/c/a20f0ccf45708af6e063c7234c215d364b00de25
- https://git.kernel.org/stable/c/f5869dfaa89854dcf34121036294d42d6c7acb8f
- https://git.kernel.org/stable/c/f8f5a8f48c7cae3fac85e04b593bd47939f9725f