CVE-2026-72076

Summary

In the Linux kernel, the following vulnerability has been resolved:

Input: ims-pcu - fix out-of-bounds read in ims_pcu_irq() debug logging

The debug logging in ims_pcu_irq() unconditionally prints data from pcu->urb_in_buf. However, if the interrupt fired for pcu->urb_ctrl, the actual data resides in pcu->urb_ctrl_buf. If urb->actual_length for the control URB exceeds pcu->max_in_size, this leads to an out-of-bounds read.

Fix this by printing from the correct buffer associated with the URB.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux628329d52474323938a03826941e166bc7c8eff4 < 4d2553e9a76a11500ec670cbe16b7fd3da4832deaffected
LinuxLinux628329d52474323938a03826941e166bc7c8eff4 < b746e853721dee91e4234c033d1b90f4605705bbaffected
LinuxLinux628329d52474323938a03826941e166bc7c8eff4 < e6153407d7edabc6ff98f0fda415d556c0bcb57aaffected
LinuxLinux628329d52474323938a03826941e166bc7c8eff4 < 3fd7c0ace245334f2a0bd29fdcb680ad56e9b275affected
LinuxLinux628329d52474323938a03826941e166bc7c8eff4 < 20fbf3ca0259d00664d1ede88837e1f11b49a88eaffected
LinuxLinux628329d52474323938a03826941e166bc7c8eff4 < 9c964fc9507aeab74376ba9f892cf84ad6950dfeaffected
LinuxLinux628329d52474323938a03826941e166bc7c8eff4 < f97bfc1a0766802a99167b3dc62d1ee7dca929feaffected
LinuxLinux628329d52474323938a03826941e166bc7c8eff4 < 403b0a6970b1084bb27907c0f8225801fdd0fe1daffected
LinuxLinux3.10affected
LinuxLinux0 < 3.10unaffected
LinuxLinux5.10.261 <= 5.10.*unaffected
LinuxLinux5.15.212 <= 5.15.*unaffected
LinuxLinux6.1.178 <= 6.1.*unaffected
LinuxLinux6.6.145 <= 6.6.*unaffected
LinuxLinux6.12.97 <= 6.12.*unaffected
LinuxLinux6.18.40 <= 6.18.*unaffected
LinuxLinux7.1.5 <= 7.1.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References