CVE-2026-68369: usb: gadget: printer: fix infinite loop in printer_read()
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: printer: fix infinite loop in printerread()
printerread() uses the same variable for the requested copy size and the number of bytes actually copied to user space. copytouser() returns the number of bytes not copied, so when it fails to copy anything, the computed copied length becomes zero.
In that case len, buf, currentrxbytes and currentrxbuf are left unchanged. If RX data is available and the user buffer remains unwritable, the read loop can repeat indefinitely.
Track the copied length separately and return -EFAULT, or the number of bytes already copied, if an iteration makes no progress.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-68369?
CVE-2026-68369 has a risk level of 17, indicating a high severity vulnerability in the Linux kernel.
What issues does CVE-2026-68369 cause?
CVE-2026-68369 can lead to an infinite loop in the printer_read() function, causing denial of service.
How do I fix CVE-2026-68369?
To fix CVE-2026-68369, ensure that you update your Linux kernel to the latest version where the vulnerability is patched.
Which software is affected by CVE-2026-68369?
CVE-2026-68369 affects the Linux kernel, particularly the USB gadget printer functionality.
When was CVE-2026-68369 published?
CVE-2026-68369 was published on August 10, 2026.