SEPTEMBER 23, 2026
Live Feed
Back to database
Case File

CVE-2026-72076

UNKNOWN · CVSS N/A EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-08-15 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's ims-pcu module, where an out-of-bounds read can occur during debug logging due to incorrect buffer access. This flaw could potentially lead to information leakage or system instability if exploited. Organizations using affected Linux kernel versions should prioritize patching this vulnerability to mitigate risks associated with unauthorized data access.

CVE
CVE-2026-72076
Severity
UNKNOWN
CVSS
N/A
EPSS
0.22%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - fix out-of-bounds read in ims_pcu_irq() debug logging The debug logging in ims_pcu_irq() unconditionally prints data from pcu->urb_in_buf. However, if the interrupt fired for pcu->urb_ctrl, the actual data resides in pcu->urb_ctrl_buf. If urb->actual_length for the control URB exceeds pcu->max_in_size, this leads to an out-of-bounds read. Fix this by printing from the correct buffer associated with the URB.