CVE-2026-72076

Source
https://cve.org/CVERecord?id=CVE-2026-72076
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72076.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72076
Downstream
Published
2026-08-15T05:52:26Z
Modified
2026-08-18T03:31:21Z
Summary
Input: ims-pcu - fix out-of-bounds read in ims_pcu_irq() debug logging
Details

In the Linux kernel, the following vulnerability has been resolved:

Input: ims-pcu - fix out-of-bounds read in ims_pcu_irq() debug logging

The debug logging in ims_pcu_irq() unconditionally prints data from pcu->urb_in_buf. However, if the interrupt fired for pcu->urb_ctrl, the actual data resides in pcu->urb_ctrl_buf. If urb->actual_length for the control URB exceeds pcu->max_in_size, this leads to an out-of-bounds read.

Fix this by printing from the correct buffer associated with the URB.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72076.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
628329d52474323938a03826941e166bc7c8eff4
Fixed
4d2553e9a76a11500ec670cbe16b7fd3da4832de
Fixed
b746e853721dee91e4234c033d1b90f4605705bb
Fixed
e6153407d7edabc6ff98f0fda415d556c0bcb57a
Fixed
3fd7c0ace245334f2a0bd29fdcb680ad56e9b275
Fixed
20fbf3ca0259d00664d1ede88837e1f11b49a88e
Fixed
9c964fc9507aeab74376ba9f892cf84ad6950dfe
Fixed
f97bfc1a0766802a99167b3dc62d1ee7dca929fe
Fixed
403b0a6970b1084bb27907c0f8225801fdd0fe1d

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72076.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.10.0
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72076.json"