In the Linux kernel, the following vulnerability has been resolved:
hwmon: (corsair-cpro) Validate the size of the received input buffer
Add bufferrecvsize to store the size of the received bytes. Validate bufferrecvsize in sendusbcmd().