CVE-2026-68366
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer uvc_send_response() builds the UVC control response from a user-supplied struct uvc_request_data: req->length = min_t(unsigned int, uvc->event_length, data->length); ... memcpy(req->buf, data->data, req->length); req->length is clamped to uvc->event_length, which is taken from the host control request wLength (up to UVC_MAX_REQUEST_SIZE, 64), and to data->length, which comes from the UVCIOC_SEND_RESPONSE ioctl and is only checked for being negative. The source buffer data->data is only 60 bytes, so a response with uvc->event_length and data->length both greater than 60 makes memcpy() read past the end of data->data. Clamp req->length to sizeof(data->data) as well.
Affected versions
Linux kernel versions
3.10
and later are affected. Fixed in
5.10.265,
5.15.216,
6.1.183,
6.6.148,
6.12.101,
6.18.42,
7.1.6,
7.2
and their respective stable series.
References
8 totalFrequently asked questions
-
What is CVE-2026-68366?
CVE-2026-68366 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 3.10 onward and has been patched in 5.10.265, 5.15.216, 6.1.183 and others. CVE-2026-68366 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
Is there a patch available for CVE-2026-68366?
Yes. CVE-2026-68366 has been patched. Fixed versions include 5.10.265, 5.15.216, 6.1.183 and others. If you are running Linux kernel 3.10 or later up to the fix versions, apply the relevant patch for your kernel branch.
-
Is CVE-2026-68366 actively exploited?
No. CVE-2026-68366 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.