Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-97540— net: usb: pegasus: don't rely on id table pointer arithmetic

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: 网络子系统:USB 驱动 pegasus:不应依赖 ID 表指针运算 当涉及动态 ID 时,当前代码存在缺陷;在此类情况下, 函数的 参数位于堆上,进行指针运算会导致索引严重越界。与其维护一个用于附加信息的侧表(side table),不如直接使用 中的 字段。 为此,动态 ID 解析代码也需要进行更新:改为仅向预留给动态 ID 的条目写入数据,并移除原有的异常循环逻辑。

AI Predicted 6.5 Difficulty: Moderate EPSS 0.21% · P10

Possible ATT&CK Techniques 1 AI

T1068 · Exploitation for Privilege Escalation

Affected Version Matrix 14

VendorProduct Version RangeStatus
Linux Linux 733260ff9c45bd4db60f45d17e8560a4a68dff4d< 7c940a1100cb0aa18a54dc48d736c0525c0f400c affected
733260ff9c45bd4db60f45d17e8560a4a68dff4d< 05d47f540d85c8f6697ec5cfc1aa7b4f96a5b31b affected
733260ff9c45bd4db60f45d17e8560a4a68dff4d< 9425a13960ef38bac237608f25c9ee64ff113086 affected
733260ff9c45bd4db60f45d17e8560a4a68dff4d< 7654812b65047349ea4c111eed42c4315a00e462 affected
733260ff9c45bd4db60f45d17e8560a4a68dff4d< 61b84e964a829d534f24eab4cbd4035d22b52601 affected
733260ff9c45bd4db60f45d17e8560a4a68dff4d< ce8101c331956bbd3e20681331dfd22eb7c1c1ea affected
2.6.16 affected
< 2.6.16 unaffected
… +6 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-97540

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
net: usb: pegasus: don't rely on id table pointer arithmetic
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: net: usb: pegasus: don't rely on id table pointer arithmetic The current code is broken when dynamic ID is involved; in such cases usb_device_id parameter of probe lives on the heap and the pointer arithmetic will get an index that is wildly out of bound. Instead of keeping a side table for additional information, use driver_info field of the usb_device_id. The dynamic ID parsing code needs to be updated for this; convert it to just write to the reserved entry for dynamic ID and remove the weird loop.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 733260ff9c45bd4db60f45d17e8560a4a68dff4d ~ 7c940a1100cb0aa18a54dc48d736c0525c0f400c -
Linux Linux 2.6.16 -

II. Public POCs for CVE-2026-97540

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-97540

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-97540 (5)

Same Patch Batch · Linux · 2026-09-25 · 372 CVEs total

CVE-2026-100075 9.8 CRITICAL RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters
CVE-2026-97957 8.8 HIGH net: hinic: fix mailbox segment buffer overflow
CVE-2026-97527 8.8 HIGH scsi: qla2xxx: Serialize NVMe unsol ctx list with a per-fcport lock
CVE-2026-97528 8.8 HIGH scsi: qla2xxx: Unlink NVMe unsol ctx before freeing on LS reject error
CVE-2026-97555 8.8 HIGH smb: client: fix heap overflow in DACL owner/group rewrite
CVE-2026-98115 8.8 HIGH ksmbd: safely drain sessions during logoff
CVE-2026-97525 8.2 HIGH x86/mm/pat: Allocate split page tables as kernel page tables
CVE-2026-97573 8.1 HIGH bnxt_en: Handle buffer allocation failure in bnxt_rx_ring_reset()
CVE-2026-98070 8.1 HIGH net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks()
CVE-2026-97570 8.1 HIGH bnxt_en: Bound SW TPA IDs to prevent crashes
CVE-2026-98069 8.1 HIGH net/rds: acquire the fastpath locks in rds_conn_shutdown()
CVE-2026-98130 8.1 HIGH sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START
CVE-2026-98116 7.8 HIGH ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF
CVE-2026-97548 7.8 HIGH xfs: fix the rtrmap and rtrefcount _maxlevels_ondisk functions
CVE-2026-97903 7.8 HIGH exit: hold a reference to thread_pid across proc_flush_pid
CVE-2026-97611 7.8 HIGH net: openvswitch: fix use-after-free of the flow table mask array
CVE-2026-97612 7.8 HIGH net: mpls: clear inner_protocol when the last label is popped
CVE-2026-98073 7.8 HIGH net: Remove conflicting altnames for dying netns in __dev_change_net_namespace().
CVE-2026-97602 7.8 HIGH inet: frags: invalidate queues before flushing them
CVE-2026-97577 7.8 HIGH media: verisilicon: rockchip: reject AV1 frames exceeding the tile capacity

Showing top 20 of 372 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-97540

No comments yet


Leave a comment