In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: printer: fix infinite loop in printer_read()
printerread() uses the same variable for the requested copy size and the number of bytes actually copied to user space. copyto_user() returns the number of bytes not copied, so when it fails to copy anything, the computed copied length becomes zero.
In that case len, buf, currentrxbytes and currentrxbuf are left unchanged. If RX data is available and the user buffer remains unwritable, the read loop can repeat indefinitely.
Track the copied length separately and return -EFAULT, or the number of bytes already copied, if an iteration makes no progress.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68369.json",
"cna_assigner": "Linux"
}