Answer in brief
CVE-2026-93120 records a Unknown severity vulnerability in usb: gadget: configfs: fix out-of-bounds read of qw_sign. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=76180d716f91f035d9c8639497cf5459b44e1a51 <b895dbed8ac9e12a5ffa1a2165575a8469f8340d || >=76180d716f91f035d9c8639497cf5459b44e1a51 <9b45125501aad2dff7730970461b455b0e0658ee || >=76180d716f91f035d9c8639497cf5459b44e1a51 <f6da500b0f8106882598b6dec87fe37d653946cf || >=76180d716f91f035d9c8639497cf5459b44e1a51 <a28c486434634f6d1e120711d2b09f3eddea6c98 || >=76180d716f91f035d9c8639497cf5459b44e1a51 <7e94cb967778e074411940db4db97f22ed77560c || >=76180d716f91f035d9c8639497cf5459b44e1a51 <afbf39c0f2297c6abef6d670a82a2079b0836191 || >=76180d716f91f035d9c8639497cf5459b44e1a51 <36315a330e067f7773196940552feacb1debbef1 || >=76180d716f91f035d9c8639497cf5459b44e1a51 <f63edb54d8f738f9c21e2068c777ae1c097df6b7 | b895dbed8ac9e12a5ffa1a2165575a8469f8340d, 9b45125501aad2dff7730970461b455b0e0658ee, f6da500b0f8106882598b6dec87fe37d653946cf, a28c486434634f6d1e120711d2b09f3eddea6c98, 7e94cb967778e074411940db4db97f22ed77560c, afbf39c0f2297c6abef6d670a82a2079b0836191, 36315a330e067f7773196940552feacb1debbef1, f63edb54d8f738f9c21e2068c777ae1c097df6b7 |
| Linux/Linuxgeneric | 4.13 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: configfs: fix out-of-bounds read of qw_sign os_desc_qw_sign_show() passes OS_STRING_QW_SIGN_LEN as the input length to utf16s_to_utf8s(), but that argument counts UTF-16 code units while OS_STRING_QW_SIGN_LEN (14) is the byte size of qw_sign[]. The array holds only OS_STRING_QW_SIGN_LEN / 2 (7) code units, so the conversion reads up to 7 units (14 bytes) past the end of qw_sign[] into the following members of struct gadget_info when the stored signature fills the array without a NUL terminator, exposing those bytes through the configfs attribute. The store path halves the count for its input bound but passes the full byte count as the utf8s_to_utf16s() output limit; use the destination code-unit count in both directions.
Quoted source text, attributed separately from HOL analysis.