CVE-2026-68184
CVE CVE-2026-68184EUVD EUVD-2026-55285Published 2026-08-10T11:59:56.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: cdrom: fix stack out-of-bounds read in CDROMVOLCTRL mmc_ioctl_cdrom_volume() first reads the audio control mode page into a 32-byte stack buffer with cgc->buflen set to 24. If the device reports a block descriptor, the function increases cgc->buflen to include that descriptor and reads the page again. For CDROMVOLCTRL, the function then builds a MODE SELECT parameter list by moving cgc->buffer forward by offset - 8 bytes. This drops the block descriptor from the outgoing payload and leaves a new 8-byte mode parameter header in front of the audio control page. However, cgc->buflen is left unchanged. With a standard 8-byte block descriptor, cgc->buffer points at buffer + 8 but cgc->buflen remains 32. cdrom_mode_select() therefore asks the low level packet path to write 32 bytes from that adjusted pointer, reading 8 bytes past the end of the 32-byte stack buffer. This is not hit by CDROMVOLREAD, and CDROMVOLCTRL only triggers it on drives that return a non-zero block descriptor length, which helps explain why it has gone unnoticed. The overread is also sent to the device as extra MODE SELECT payload, so it may not produce an obvious local failure. Reduce cgc->buflen by the same amount as the buffer pointer adjustment so the MODE SELECT transfer covers only the intended parameter list.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <d43c5c0c935522deae7339e0c2399365f3bf0016; patch: 6.18.42; patch: 7.1.6; 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <b27e195d4db8dea263050bdbeb11881b2999c9c6; patch: 7.2-rc5; 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <35b68e24c5a69fa4545f46f05f6c849223034cb6; patch: 6.6.148; patch: 0; 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <7344c84e32413e5c8832f74b8a612b0194e5c051; patch: 6.12.101; 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <f3e2715a150066f09aa82c30fa983fb184ad6dd5; 2.6.12
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.