Bug 2502352 (CVE-2026-63943) - CVE-2026-63943 kernel: Input: xpad - fix out-of-bounds access for Share button
Summary: CVE-2026-63943 kernel: Input: xpad - fix out-of-bounds access for Share button
Keywords:
Status: NEW
Alias: CVE-2026-63943
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-19 16:03 UTC by OSIDB Bzimport
Modified: 2026-07-21 22:04 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-19 16:03:28 UTC
In the Linux kernel, the following vulnerability has been resolved:

Input: xpad - fix out-of-bounds access for Share button

xpadone_process_packet() receives len directly from urb->actual_length
and uses it to index the share-button byte at data[len - 18] or
data[len - 26]. Since both len and data[0] are under the device's
control, a broken controller can send a GIP_CMD_INPUT packet with
actual_length < 18 (e.g. 5 bytes) and reach this code path, causing
accesses beyond the actual array.

Fix this by calculating the offset and checking bounds against the
packet length.


Note You need to log in before you can comment on or make changes to this bug.