CVE-2026-63943
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
19/07/2026
Última modificación:
27/07/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
Input: xpad - fix out-of-bounds access for Share button<br />
<br />
xpadone_process_packet() receives len directly from urb->actual_length<br />
and uses it to index the share-button byte at data[len - 18] or<br />
data[len - 26]. Since both len and data[0] are under the device&#39;s<br />
control, a broken controller can send a GIP_CMD_INPUT packet with<br />
actual_length
Impacto
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/37ec54abfdd63a63fd50734a9c4e4cbc1e5795af
- https://git.kernel.org/stable/c/6346b0895b574ce45f3747b9c508c72f70e6abef
- https://git.kernel.org/stable/c/6cdc46b38cf146ce81d4831b6472dbf7731849a2
- https://git.kernel.org/stable/c/9749db57233b396353ad5dee81eec9d9880c9246
- https://git.kernel.org/stable/c/bcfb4833cd4078a1a356ef451838b75cd233099e



