CVE-2026-68088

Source
https://cve.org/CVERecord?id=CVE-2026-68088
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68088.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-68088
Downstream
Published
2026-08-10T11:51:42.647Z
Modified
2026-08-13T04:02:39.892073456Z
Summary
usb: gadget: function: rndis: add length check to response query
Details

In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: function: rndis: add length check to response query

Add variable representations for BufLength and BufOffset in rndisqueryresponse(), and perform a length check on them.

This is identical to how rndissetresponse() handles these parameters.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68088.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
340600ab4cf0cc41efd01a65af97ebb7d35a7f85
Fixed
efcf4e4eeea0d69d8da72a7bc5cbd49b6192260e
Fixed
bb2b4402b4571b0c989b977779f7be01107ca425
Fixed
585921866d2d7d65d4b0d89927c78f784668cf5f
Fixed
caea8b120604312bab2bfeb1a972f9cd17019e93
Fixed
f5870777458d8be65d7cd08bc750a03f17998350
Fixed
e01e7814b4223560eab0513b7c15b8c82bdc83f3
Fixed
b09716040f3fa4a252eeda3ceb5295ea0e39c1fb
Fixed
95f90eea070837f7c72207d5520f805bdefc3bc5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68088.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.13
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.96
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.39
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68088.json"