PT-2026-61212 · Linux+1 · Linux Kernel+1

CVE-2026-63895

·

Published

2026-07-19

·

Updated

2026-09-07

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the f fs gadget driver where the ffs ep0 read() function allocates a control-OUT data buffer using kmalloc() based on the length specified in the Setup packet. When a short control OUT transfer occurs, the ffs ep0 queue wait() function returns the actual number of bytes received, which is less than the allocated length. However, the subsequent copy to user() call copies the full allocated length to userspace. This results in uninitialized slab residue—leftover data from previous memory allocations—being delivered to the FunctionFS daemon. This condition is reachable via the FunctionFS device node, typically owned by privileged gadget daemons such as adbd or UMS.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-63895
OPENSUSE-SU-2026:21555-1
SUSE-SU-2026:23066-1
SUSE-SU-2026:23068-1
SUSE-SU-2026:23193-1
SUSE-SU-2026:23194-1
SUSE-SU-2026:23221-1
SUSE-SU-2026:23231-1
SUSE-SU-2026:23237-1
SUSE-SU-2026:23241-1
SUSE-SU-2026:23244-1
SUSE-SU-2026:3790-1
SUSE-SU-2026:3810-1
USN-8593-1
USN-8603-1
USN-8618-1
USN-8663-1
USN-8664-1
USN-8728-1

Affected Products

Linux Kernel
Ubuntu