CVE-2026-90055

Source
https://cve.org/CVERecord?id=CVE-2026-90055
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90055.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90055
Downstream
Published
2026-09-17T16:05:40Z
Modified
2026-09-18T03:48:35Z
Summary
usb: atm: usbatm: fix invalid ci_range initialization
Details

In the Linux kernel, the following vulnerability has been resolved:

usb: atm: usbatm: fix invalid ci_range initialization

syzbot reported a shift-out-of-bounds in __vcc_connect():

UBSAN: shift-out-of-bounds in net/atm/common.c:382:32 shift exponent -1 is negative CPU: 0 UID: 0 PID: 5987 Comm: syz.0.18 Not tainted syzkaller #0 PREEMPT(full) Hardware name: Google Compute Engine/Google Compute Engine, BIOS Google 08/05/2026 Call Trace: dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120 ubsan_epilogue+0xa/0x30 lib/ubsan.c:233 __ubsan_handle_shift_out_of_bounds+0x36d/0x400 lib/ubsan.c:494 __vcc_connect+0x14b4/0x19c0 net/atm/common.c:382 vcc_connect+0x328/0x8f0 net/atm/common.c:498 pvc_bind+0x272/0x380 net/atm/pvc.c:52 __sys_bind+0x2e3/0x410 net/socket.c:1976 __x64_sys_bind+0x7a/0x90 net/socket.c:1979 ...

ATM device ci_range fields (vpi_bits and vci_bits) represent the number of bits supported for VPI and VCI addressing on the device. net/atm/common.c directly uses these fields as bit shift counts: vpi >> dev->ci_range.vpi_bits vci >> dev->ci_range.vci_bits 1 << vcc->dev->ci_range.vpi_bits 1 << vcc->dev->ci_range.vci_bits

usbatm_atm_init() sets ci_range.vpi_bits and ci_range.vci_bits to ATM_CI_MAX (-1), which is defined in <uapi/linux/atmdev.h> as a sentinel value for userspace ATM_SETCIRANGE requests, not a valid bit count. Shifting by -1 is undefined behavior and triggers UBSAN warnings.

ATM UNI cell headers allow up to 8 bits for VPI (0..255) and 16 bits for VCI (0..65535). Initialize vpi_bits to 8 and vci_bits to 16, as done by solos-pci.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90055.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
c59bba75fa500f13ef14215d599ee0d7faa1b954
Fixed
8442586526c406527bf31206e538c0ce6bc672e6
Fixed
561cbd6d49022c9a383e22a39c87a165a4d39f9c
Fixed
76bc7c3a44856744b64aa91d9afe6d9522a78c42
Fixed
7baa0c92be39eb3da755ed6f200497a57078c47b
Fixed
1e964d414bfd9f8dfe9948d08e4b9dda4ed2e422
Fixed
ff7f77a234f7b74e5955a6e34fa74eca4c9ca44c
Fixed
75667703115154a4fd9cf259d4f826d8729cbcda
Fixed
a60fd8c6dbaa76da4163cf225ed2b9e982540f39

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90055.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.13
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90055.json"