-

CVE-2026-64330

usb: typec: tcpm: Validate SVID index in svdm_consume_modes()

In the Linux kernel, the following vulnerability has been resolved:

usb: typec: tcpm: Validate SVID index in svdm_consume_modes()

In svdm_consume_modes(), the SVID value is read from pmdata->svids using
pmdata->svid_index as an array index without bounds validation:

    paltmode->svid = pmdata->svids[pmdata->svid_index];

If pmdata->svid_index is driven beyond SVID_DISCOVERY_MAX (16), it results
in an out-of-bounds read of the pmdata->svids array. Because pd_mode_data
is embedded inside struct tcpm_port, indexing past svids reads into
adjacent fields. In particular:
- At index 16, it reads the altmodes count.
- At index 18 and beyond, it reads into altmode_desc[], which contains
  partner-supplied SVDM Discovery Modes VDOs.

By injecting a chosen SVID into altmode_desc[0].vdo and driving svid_index
to 20, the partner can force paltmode->svid to be loaded with an arbitrary,
partner- chosen SVID, which is then registered via
typec_partner_register_altmode().

Fix this by validating that pmdata->svid_index is non-negative and strictly
less than pmdata->nsvids before accessing the pmdata->svids array inside
svdm_consume_modes().
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 4ab8c18d4d67321cc7b660559de17511d4fc0237
Version < 89ff289cbf5d3b659a2babc5ccaae4eaf7e7cf53
Status affected
Version 4ab8c18d4d67321cc7b660559de17511d4fc0237
Version < d638ec188e95fe60f4b01106ffd41958f8fb3c2c
Status affected
Version 4ab8c18d4d67321cc7b660559de17511d4fc0237
Version < f8163c414de8640f2ca82ce4dc93409d4cdc2fad
Status affected
Version 4ab8c18d4d67321cc7b660559de17511d4fc0237
Version < 012406f89abc52d1d5f07aa5653b519ebf6d2407
Status affected
Version 4ab8c18d4d67321cc7b660559de17511d4fc0237
Version < c6d2af3b217a525741c472f0ab45d7d274b8468f
Status affected
Version 4ab8c18d4d67321cc7b660559de17511d4fc0237
Version < 3e1b1ac47e8163627f159f30d80d51b914620dd4
Status affected
Version 4ab8c18d4d67321cc7b660559de17511d4fc0237
Version < 313ca06e7e224ca1dfadd5722fe71fb8bc276b8b
Status affected
Version 4ab8c18d4d67321cc7b660559de17511d4fc0237
Version < 7b681dd5fbf60b24a13c14661e5b7735759fb491
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 4.19
Status affected
Version 0
Version < 4.19
Status unaffected
Version <= 5.10.*
Version 5.10.261
Status unaffected
Version <= 5.15.*
Version 5.15.212
Status unaffected
Version <= 6.1.*
Version 6.1.178
Status unaffected
Version <= 6.6.*
Version 6.6.145
Status unaffected
Version <= 6.12.*
Version 6.12.96
Status unaffected
Version <= 6.18.*
Version 6.18.39
Status unaffected
Version <= 7.1.*
Version 7.1.4
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.075
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/89ff289cbf5d3b659a2babc5ccaae4eaf7e7cf53
https://git.kernel.org/stable/c/d638ec188e95fe60f4b01106ffd41958f8fb3c2c
https://git.kernel.org/stable/c/f8163c414de8640f2ca82ce4dc93409d4cdc2fad
https://git.kernel.org/stable/c/012406f89abc52d1d5f07aa5653b519ebf6d2407
https://git.kernel.org/stable/c/c6d2af3b217a525741c472f0ab45d7d274b8468f
https://git.kernel.org/stable/c/3e1b1ac47e8163627f159f30d80d51b914620dd4
https://git.kernel.org/stable/c/313ca06e7e224ca1dfadd5722fe71fb8bc276b8b
https://git.kernel.org/stable/c/7b681dd5fbf60b24a13c14661e5b7735759fb491