CVE-2026-93120
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: configfs: fix out-of-bounds read of qw_sign os_desc_qw_sign_show() passes OS_STRING_QW_SIGN_LEN as the input length to utf16s_to_utf8s(), but that argument counts UTF-16 code units while OS_STRING_QW_SIGN_LEN (14) is the byte size of qw_sign[]. The array holds only OS_STRING_QW_SIGN_LEN / 2 (7) code units, so the conversion reads up to 7 units (14 bytes) past the end of qw_sign[] into the following members of struct gadget_info when the stored signature fills the array without a NUL terminator, exposing those bytes through the configfs attribute. The store path halves the count for its input bound but passes the full byte count as the utf8s_to_utf16s() output limit; use the destination code-unit count in both directions.
What this means for your business
What to do
- 1Ask your IT team or provider whether any of your systems use the affected product.
- 2If you do, follow the vendor's guidance. No patch reference has been published yet.
Not sure if your company is exposed?
Fastnexa’s certified penetration testers can check whether attackers could use this flaw, or others like it, against your websites, apps and network. The full test is free for our first 10 founding clients until 31 December 2026.
Scoring
- CVSS
- Not yet scored
- Assigned by
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Dates
- Published
- 2026-09-17
- Last modified
- 2026-09-17
- Sources
- NVD
References
- https://git.kernel.org/stable/c/36315a330e067f7773196940552feacb1debbef1
- https://git.kernel.org/stable/c/7e94cb967778e074411940db4db97f22ed77560c
- https://git.kernel.org/stable/c/9b45125501aad2dff7730970461b455b0e0658ee
- https://git.kernel.org/stable/c/a28c486434634f6d1e120711d2b09f3eddea6c98
- https://git.kernel.org/stable/c/afbf39c0f2297c6abef6d670a82a2079b0836191
- https://git.kernel.org/stable/c/b895dbed8ac9e12a5ffa1a2165575a8469f8340d
- https://git.kernel.org/stable/c/f63edb54d8f738f9c21e2068c777ae1c097df6b7
- https://git.kernel.org/stable/c/f6da500b0f8106882598b6dec87fe37d653946cf