cbcvebase.
CVE-2026-31720
published 2026-05-01

CVE-2026-31720: In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_uac1_legacy: validate control request size f_audio_complete() copies…

PriorityP343high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.13%
3.0th percentile
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_uac1_legacy: validate control request size f_audio_complete() copies req->length bytes into a 4-byte stack variable: u32 data = 0; memcpy(&data, req->buf, req->length); req->length is derived from the host-controlled USB request path, which can lead to a stack out-of-bounds write. Validate req->actual against the expected payload size for the supported control selectors and decode only the expected amount of data. This avoids copying a host-influenced length into a fixed-size stack object.

Affected

54 ranges· showing 25
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= c6994e6f067cf0fc4c6cca3d164018b1150916f8 < 557d1d4e862eccd0b74cc377b66de3e1e8d49605557d1d4e862eccd0b74cc377b66de3e1e8d49605
linuxlinux>= c6994e6f067cf0fc4c6cca3d164018b1150916f8 < 21b11e8581285c6f10ef43d05df349d445f2427321b11e8581285c6f10ef43d05df349d445f24273
linuxlinux>= c6994e6f067cf0fc4c6cca3d164018b1150916f8 < 0d41772d98dcaf6c17e875b7d0ea0154ae1191ee0d41772d98dcaf6c17e875b7d0ea0154ae1191ee
linuxlinux>= c6994e6f067cf0fc4c6cca3d164018b1150916f8 < c6da4fed7537aec19880c24f6c3a95065adb1406c6da4fed7537aec19880c24f6c3a95065adb1406
linuxlinux>= c6994e6f067cf0fc4c6cca3d164018b1150916f8 < be2d32f0c3fe333d14c0a9ca90328dacbc3e06b8be2d32f0c3fe333d14c0a9ca90328dacbc3e06b8
linuxlinux>= c6994e6f067cf0fc4c6cca3d164018b1150916f8 < 8e5eb1d6e6a3d7bbea9c92132d0cda57931764268e5eb1d6e6a3d7bbea9c92132d0cda5793176426
linuxlinux>= c6994e6f067cf0fc4c6cca3d164018b1150916f8 < 26304d124e7f0383f8fe1168b5801a0ac7e16b1c26304d124e7f0383f8fe1168b5801a0ac7e16b1c
linuxlinux>= c6994e6f067cf0fc4c6cca3d164018b1150916f8 < 6e0e34d85cd46ceb37d16054e97a373a32770f6c6e0e34d85cd46ceb37d16054e97a373a32770f6c
linuxlinux_kernel
linuxlinux_kernel>= 2.6.31 < 5.10.2535.10.253
linuxlinux_kernel>= 5.11 < 5.15.2035.15.203
linuxlinux_kernel>= 5.16 < 6.1.1686.1.168
linuxlinux_kernel>= 6.13 < 6.18.226.18.22
linuxlinux_kernel>= 6.19 < 6.19.126.19.12
linuxlinux_kernel>= 6.2 < 6.6.1346.6.134
linuxlinux_kernel>= 6.7 < 6.12.816.12.81
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-5.15
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-5.15
ubuntulinux-azure-6.8
ubuntulinux-azure-fde

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_ubuntu7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.