| 概要 | In the Linux kernel, the following vulnerability has been resolved: USB: serial: io_ti: fix heap overflow in get_manuf_info() get_manuf_info() reads le16_to_cpu(rom_desc->Size) bytes from the The Size field comes from the device and is only validated (in valid_csum() is called after read_rom() and also iterates Fix by rejecting descriptors with unexpected length before calling [ johan: amend commit message; also check for short descriptors ] |
|---|---|
| 公表日 | 2026年6月25日18:16 |
| 登録日 | 2026年6月27日4:26 |
| 最終更新日 | 2026年6月25日18:16 |