-

CVE-2026-80827

Medienbericht

USB: serial: option: fix slab OOB read in interrupt URB callback

In the Linux kernel, the following vulnerability has been resolved:

USB: serial: option: fix slab OOB read in interrupt URB callback

The interrupt URB buffer is allocated in setup_port_interrupt_in() based
on the endpoint's wMaxPacketSize:

    buffer_size = usb_endpoint_maxp(epd);
    port->interrupt_in_buffer = kmalloc(buffer_size, GFP_KERNEL);

When a USB device declares wMaxPacketSize = 8 on its interrupt IN
endpoint, the buffer is allocated from kmalloc-8 cache (exactly
8 bytes).

If the device sends a short packet (actual_length < wMaxPacketSize),
the URB completes with status == 0 and the callback proceeds to read:

    data[sizeof(struct usb_ctrlrequest)]

which evaluates to data[8], accessing 1 byte beyond the allocated 8-byte
buffer. This results in a slab out-of-bounds read.

Fix this by adding the missing bounds check: first verify that the
actual length is large enough to contain the struct usb_ctrlrequest
header before accessing req_pkt->bRequestType and req_pkt->bRequest,
and then verify that there is an additional byte for the modem signal
state before reading data[sizeof(struct usb_ctrlrequest)] inside the
conditional.  Use sizeof(*req_pkt) instead of sizeof(struct
usb_ctrlrequest) for consistency.

[ johan: use dev_err(); split signals declaration and initialisation ]
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 58cfe9113e485f7e04bd0eac4fc4251b330af501
Version < fbe60fd2abc8a5561f39719a41ad9a01b5d8e567
Status affected
Version 58cfe9113e485f7e04bd0eac4fc4251b330af501
Version < 94e5525697b9e91ddc4071129874120a50a4f342
Status affected
Version 58cfe9113e485f7e04bd0eac4fc4251b330af501
Version < 6b8cf5422c7e96ed5b22a8368eff663f3f98b8ec
Status affected
Version 58cfe9113e485f7e04bd0eac4fc4251b330af501
Version < 030e3a73d3c3aa67c44454649e984d6383cdb7d3
Status affected
Version 58cfe9113e485f7e04bd0eac4fc4251b330af501
Version < 060db7d48af1e650643c8b8319111a9ea2ce4486
Status affected
Version 58cfe9113e485f7e04bd0eac4fc4251b330af501
Version < 2ef5560387f2c0713cee975be2b24b281bd90f3e
Status affected
Version 58cfe9113e485f7e04bd0eac4fc4251b330af501
Version < a72a13c83a652516a0e469d275b81d29a7429049
Status affected
Version 58cfe9113e485f7e04bd0eac4fc4251b330af501
Version < d762aef4eba354066be21a5d88eb2066e282f4c9
Status affected
Version 58cfe9113e485f7e04bd0eac4fc4251b330af501
Version < 885d802f544ca7bfa8f3984d94233cce715bb6b3
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.12
Status affected
Version 0
Version < 2.6.12
Status unaffected
Version <= 5.10.*
Version 5.10.269
Status unaffected
Version <= 5.15.*
Version 5.15.220
Status unaffected
Version <= 6.1.*
Version 6.1.187
Status unaffected
Version <= 6.6.*
Version 6.6.156
Status unaffected
Version <= 6.12.*
Version 6.12.108
Status unaffected
Version <= 6.18.*
Version 6.18.49
Status unaffected
Version <= 7.1.*
Version 7.1.13
Status unaffected
Version <= 7.2.*
Version 7.2.3
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.093
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
08.09.2026 20:38
https://git.kernel.org/stable/c/fbe60fd2abc8a5561f39719a41ad9a01b5d8e567
https://git.kernel.org/stable/c/94e5525697b9e91ddc4071129874120a50a4f342
https://git.kernel.org/stable/c/6b8cf5422c7e96ed5b22a8368eff663f3f98b8ec
https://git.kernel.org/stable/c/030e3a73d3c3aa67c44454649e984d6383cdb7d3
https://git.kernel.org/stable/c/060db7d48af1e650643c8b8319111a9ea2ce4486
https://git.kernel.org/stable/c/2ef5560387f2c0713cee975be2b24b281bd90f3e
https://git.kernel.org/stable/c/a72a13c83a652516a0e469d275b81d29a7429049
https://git.kernel.org/stable/c/d762aef4eba354066be21a5d88eb2066e282f4c9
https://git.kernel.org/stable/c/885d802f544ca7bfa8f3984d94233cce715bb6b3