---
id: CVE-2026-93120
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  usb: gadget: configfs: fix out-of-bounds read of qw_sign

  os_desc_qw_sign_show() passes OS_STRING_QW_SIGN_LEN as the input
  length to utf16s_to_utf8s(), but that argumen…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  usb: gadget: configfs: fix out-of-bounds read of qw_sign

  os_desc_qw_sign_show() passes OS_STRING_QW_SIGN_LEN as the input
  length to utf16s_to_utf8s(), but that argumen…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 76180d716f91f035d9c8639497cf5459b44e1a51 <
    b895dbed8ac9e12a5ffa1a2165575a8469f8340d
  - >-
    Linux >= 76180d716f91f035d9c8639497cf5459b44e1a51 <
    9b45125501aad2dff7730970461b455b0e0658ee
  - >-
    Linux >= 76180d716f91f035d9c8639497cf5459b44e1a51 <
    f6da500b0f8106882598b6dec87fe37d653946cf
  - >-
    Linux >= 76180d716f91f035d9c8639497cf5459b44e1a51 <
    a28c486434634f6d1e120711d2b09f3eddea6c98
  - >-
    Linux >= 76180d716f91f035d9c8639497cf5459b44e1a51 <
    7e94cb967778e074411940db4db97f22ed77560c
  - >-
    Linux >= 76180d716f91f035d9c8639497cf5459b44e1a51 <
    afbf39c0f2297c6abef6d670a82a2079b0836191
  - >-
    Linux >= 76180d716f91f035d9c8639497cf5459b44e1a51 <
    36315a330e067f7773196940552feacb1debbef1
  - >-
    Linux >= 76180d716f91f035d9c8639497cf5459b44e1a51 <
    f63edb54d8f738f9c21e2068c777ae1c097df6b7
  - Linux 4.13
published: '2026-09-17'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T17:18:06.667'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93120'
references:
  - url: 'https://git.kernel.org/stable/c/36315a330e067f7773196940552feacb1debbef1'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/7e94cb967778e074411940db4db97f22ed77560c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/9b45125501aad2dff7730970461b455b0e0658ee'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/a28c486434634f6d1e120711d2b09f3eddea6c98'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/afbf39c0f2297c6abef6d670a82a2079b0836191'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/b895dbed8ac9e12a5ffa1a2165575a8469f8340d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/f63edb54d8f738f9c21e2068c777ae1c097df6b7'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/f6da500b0f8106882598b6dec87fe37d653946cf'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-17T16:21:47.751Z'
epss: 0.0022
epssPercentile: 0.11115
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: configfs: fix out-of-bounds read of qw_sign

os_desc_qw_sign_show() passes OS_STRING_QW_SIGN_LEN as the input
length to utf16s_to_utf8s(), but that argument counts UTF-16 code
units while OS_STRING_QW_SIGN_LEN (14) is the byte size of qw_sign[].
The array holds only OS_STRING_QW_SIGN_LEN / 2 (7) code units, so the
conversion reads up to 7 units (14 bytes) past the end of qw_sign[]
into the following members of struct gadget_info when the stored
signature fills the array without a NUL terminator, exposing those
bytes through the configfs attribute.

The store path halves the count for its input bound but passes the
full byte count as the utf8s_to_utf16s() output limit; use the
destination code-unit count in both directions.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
