Threats Tagged 'ghsa-5hvq-fg66-prgg'
View all threats tagged with 'ghsa-5hvq-fg66-prgg'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'ghsa-5hvq-fg66-prgg'
Click on any threat for detailed analysis and mitigation recommendations
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling The… (CVE-2026-63896)CVE-2026-63896 0 A vulnerability in the Linux kernel's USB gadget composite driver related to WebUSB GET_URL handling causes an integer underflow. This underflow can lead to an out-of-bounds memory copy when the host supplies a small wLength value, potentially causing memory corruption. The issue arises because the code subtracts a constant from wLength without checking if wLength is smaller than that constant, resulting in an unsigned wraparound. The vulnerability is triggered by a USB host sending a crafted SETUP packet to a gadget with webusb/use=1 and a landingPage configured. The fix involves handling the small wLength case before the arithmetic to prevent the underflow and avoid copying excessive bytes. Join the discussion | GCVE Database | 07/19/2026, 18:31:44 UTC Added: 07/19/2026, 19:38:19 UTC |
Showing 1 to 1 of 1 result