CVE-2026-72074

Source
https://cve.org/CVERecord?id=CVE-2026-72074
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72074.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72074
Downstream
Published
2026-08-15T05:52:25.418Z
Modified
2026-08-18T03:31:11.095865889Z
Summary
Input: ims-pcu - fix type confusion in CDC union descriptor parsing
Details

In the Linux kernel, the following vulnerability has been resolved:

Input: ims-pcu - fix type confusion in CDC union descriptor parsing

The driver currently trusts the bMasterInterface0 from the CDC union descriptor without verifying that it matches the interface being probed. This could lead to the driver overwriting the private data of another interface.

Validate that the control interface found in the descriptor is indeed the one we are probing.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72074.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
628329d52474323938a03826941e166bc7c8eff4
Fixed
ab87cd7789d00f441f60a016cbcff35abe76513c
Fixed
b5518c5632f3485849421b9c33b4db5ae6a54ed7
Fixed
163c3e7a1de6b3d5c85edb3bdf4cf087382103b0
Fixed
08bf4b6ee28987570f4b3f1954427621fa291bf5
Fixed
fa7f65c5315a25b310daae69ab527efd420e37fa
Fixed
0e8115a7ed9a99ff9495615a575a6c0f43566d10
Fixed
f4cf878dcc4f6f02e7a25294bfaed4361264995e
Fixed
ca459e237bc49567649c56bc72e4c602fb92fd67

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72074.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.10.0
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72074.json"