-
CVE-2026-80827
- EPSS 0.2%
- Veröffentlicht 04.09.2026 15:54:31
- Zuletzt bearbeitet 04.09.2026 16:18:10
- Erkennungen
USB: serial: option: fix slab OOB read in interrupt URB callback
In the Linux kernel, the following vulnerability has been resolved:
USB: serial: option: fix slab OOB read in interrupt URB callback
The interrupt URB buffer is allocated in setup_port_interrupt_in() based
on the endpoint's wMaxPacketSize:
buffer_size = usb_endpoint_maxp(epd);
port->interrupt_in_buffer = kmalloc(buffer_size, GFP_KERNEL);
When a USB device declares wMaxPacketSize = 8 on its interrupt IN
endpoint, the buffer is allocated from kmalloc-8 cache (exactly
8 bytes).
If the device sends a short packet (actual_length < wMaxPacketSize),
the URB completes with status == 0 and the callback proceeds to read:
data[sizeof(struct usb_ctrlrequest)]
which evaluates to data[8], accessing 1 byte beyond the allocated 8-byte
buffer. This results in a slab out-of-bounds read.
Fix this by adding the missing bounds check: first verify that the
actual length is large enough to contain the struct usb_ctrlrequest
header before accessing req_pkt->bRequestType and req_pkt->bRequest,
and then verify that there is an additional byte for the modem signal
state before reading data[sizeof(struct usb_ctrlrequest)] inside the
conditional. Use sizeof(*req_pkt) instead of sizeof(struct
usb_ctrlrequest) for consistency.
[ johan: use dev_err(); split signals declaration and initialisation ]Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
58cfe9113e485f7e04bd0eac4fc4251b330af501
Version <
fbe60fd2abc8a5561f39719a41ad9a01b5d8e567
Status
affected
Version
58cfe9113e485f7e04bd0eac4fc4251b330af501
Version <
94e5525697b9e91ddc4071129874120a50a4f342
Status
affected
Version
58cfe9113e485f7e04bd0eac4fc4251b330af501
Version <
6b8cf5422c7e96ed5b22a8368eff663f3f98b8ec
Status
affected
Version
58cfe9113e485f7e04bd0eac4fc4251b330af501
Version <
030e3a73d3c3aa67c44454649e984d6383cdb7d3
Status
affected
Version
58cfe9113e485f7e04bd0eac4fc4251b330af501
Version <
060db7d48af1e650643c8b8319111a9ea2ce4486
Status
affected
Version
58cfe9113e485f7e04bd0eac4fc4251b330af501
Version <
2ef5560387f2c0713cee975be2b24b281bd90f3e
Status
affected
Version
58cfe9113e485f7e04bd0eac4fc4251b330af501
Version <
a72a13c83a652516a0e469d275b81d29a7429049
Status
affected
Version
58cfe9113e485f7e04bd0eac4fc4251b330af501
Version <
d762aef4eba354066be21a5d88eb2066e282f4c9
Status
affected
Version
58cfe9113e485f7e04bd0eac4fc4251b330af501
Version <
885d802f544ca7bfa8f3984d94233cce715bb6b3
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
2.6.12
Status
affected
Version
0
Version <
2.6.12
Status
unaffected
Version <=
5.10.*
Version
5.10.269
Status
unaffected
Version <=
5.15.*
Version
5.15.220
Status
unaffected
Version <=
6.1.*
Version
6.1.187
Status
unaffected
Version <=
6.6.*
Version
6.6.156
Status
unaffected
Version <=
6.12.*
Version
6.12.108
Status
unaffected
Version <=
6.18.*
Version
6.18.49
Status
unaffected
Version <=
7.1.*
Version
7.1.13
Status
unaffected
Version <=
7.2.*
Version
7.2.3
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.093 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://git.kernel.org/stable/c/fbe60fd2abc8a5561f39719a41ad9a01b5d8e567
https://git.kernel.org/stable/c/94e5525697b9e91ddc4071129874120a50a4f342
https://git.kernel.org/stable/c/6b8cf5422c7e96ed5b22a8368eff663f3f98b8ec
https://git.kernel.org/stable/c/030e3a73d3c3aa67c44454649e984d6383cdb7d3
https://git.kernel.org/stable/c/060db7d48af1e650643c8b8319111a9ea2ce4486
https://git.kernel.org/stable/c/2ef5560387f2c0713cee975be2b24b281bd90f3e
https://git.kernel.org/stable/c/a72a13c83a652516a0e469d275b81d29a7429049
https://git.kernel.org/stable/c/d762aef4eba354066be21a5d88eb2066e282f4c9
https://git.kernel.org/stable/c/885d802f544ca7bfa8f3984d94233cce715bb6b3