Back

MEDIUM

usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer

Published Aug 10, 2026

Description

uvc_send_response() builds the UVC control response from a user-supplied struct uvc_request_data:

req->length = min_t(unsigned int, uvc->event_length, data->length); ... memcpy(req->buf, data->data, req->length);

req->length is clamped to uvc->event_length, which is taken from the host control request wLength (up to UVC_MAX_REQUEST_SIZE, 64), and to data->length, which comes from the UVCIOC_SEND_RESPONSE ioctl and is only checked for being negative. The source buffer data->data is only 60 bytes, so a response with uvc->event_length and data->length both greater than 60 makes memcpy() read past the end of data->data.

Clamp req->length to sizeof(data->data) as well.

Affected products

Remediation

Red Hat statement

This issue affects USB UVC gadget mode. uvc_send_response() does not clamp user-supplied length to the response buffer. Systems not using UVC gadget are not affected.

Metrics

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Aug 10, 2026
Updated Aug 19, 2026
Reserved Jul 30, 2026
NVD
Status Received
Modified Aug 19, 2026
Red Hat
Severity Moderate
Public date Aug 10, 2026