| 概要 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_uac1_legacy: validate control request size f_audio_complete() copies req->length bytes into a 4-byte stack u32 data = 0; req->length is derived from the host-controlled USB request path, Validate req->actual against the expected payload size for the This avoids copying a host-influenced length into a fixed-size |
|---|---|
| 公表日 | 2026年5月2日0:16 |
| 登録日 | 2026年5月2日4:06 |
| 最終更新日 | 2026年5月2日0:24 |