| Summary | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_uac1_legacy: validate control request size f_audio_complete() copies req->length bytes into a 4-byte stack u32 data = 0; req->length is derived from the host-controlled USB request path, Validate req->actual against the expected payload size for the This avoids copying a host-influenced length into a fixed-size |
|---|---|
| Publication Date | May 2, 2026, 12:16 a.m. |
| Registration Date | May 2, 2026, 4:06 a.m. |
| Last Update | May 2, 2026, 12:24 a.m. |