« Volver al listado

CVE-2026-72483

Estado: RecibidaAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control()

The `max3421_hub_control()` function handles USB hub class requests to the virtual root hub. In the `default` branches of both the `ClearPortFeature` and `SetPortFeature` switch statements, it modifies `max3421_hcd->port_status` by left shifting 1 by the request's `value` parameter. However, it does not validate whether this shift will exceed the width of `port_status`.

So if a malicious userspace task with access to the root hub via /dev/bus/usb/.../001 issues a USBDEVFS_CONTROL ioctl with `wValue` greater than or equal to 32, the left shift operation invokes shift-out-of-bounds undefined behavior.

Leer descripción completaMostrar menos

This results in arbitrary bit corruption of `port_status`, including the normally-immutable change bits, which can bypass internal state checks and confuse the hub status.

Fix this by rejecting requests whose `value` exceeds the shift width before performing the shift.

This issue was found using a KLEE-based symbolic execution tool for kernel drivers that I'm currently developing.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Acceso local (AV:L) con privilegios de usuario (PR:L) permite corromper bits de puerto USB via ioctl, manipulando estado del dispositivo y causando denegación de servicio.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-72483",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2d53139f31626bad6f8983d8e519ddde2cbba921",
              "lessThan": "e5fa9d8f40746ec3447335c9642c03410f5fd3af",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2d53139f31626bad6f8983d8e519ddde2cbba921",
              "lessThan": "08b1d4cab0230697bc74c63fc4e40170a7559c54",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2d53139f31626bad6f8983d8e519ddde2cbba921",
              "lessThan": "3be5f24e8270ba53b3c814d13689bb8644c86237",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2d53139f31626bad6f8983d8e519ddde2cbba921",
              "lessThan": "d512bdefd241b98f4d7bcb5bab5614a86411fad4",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2d53139f31626bad6f8983d8e519ddde2cbba921",
              "lessThan": "00dd025324b56d39d37e57a08f473dab3a660f30",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2d53139f31626bad6f8983d8e519ddde2cbba921",
              "lessThan": "02d03c61e8a7b016956acb48e8a2512d16d87517",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2d53139f31626bad6f8983d8e519ddde2cbba921",
              "lessThan": "4da073d57176d8e1c2bca34febfbc81d2560c1a5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2d53139f31626bad6f8983d8e519ddde2cbba921",
              "lessThan": "cff06b03b530ae1fe8a13e93a7848f2130e00fb4",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/usb/host/max3421-hcd.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.16"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.16",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.261",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.212",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.178",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.145",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.97",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.40",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/usb/host/max3421-hcd.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T06:22:22.527",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/00dd025324b56d39d37e57a08f473dab3a660f30",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/02d03c61e8a7b016956acb48e8a2512d16d87517",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/08b1d4cab0230697bc74c63fc4e40170a7559c54",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3be5f24e8270ba53b3c814d13689bb8644c86237",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4da073d57176d8e1c2bca34febfbc81d2560c1a5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cff06b03b530ae1fe8a13e93a7848f2130e00fb4",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d512bdefd241b98f4d7bcb5bab5614a86411fad4",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e5fa9d8f40746ec3447335c9642c03410f5fd3af",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control()\n\nThe `max3421_hub_control()` function handles USB hub class requests\nto the virtual root hub. In the `default` branches of both the\n`ClearPortFeature` and `SetPortFeature` switch statements, it modifies\n`max3421_hcd->port_status` by left shifting 1 by the request's `value`\nparameter. However, it does not validate whether this shift will exceed\nthe width of `port_status`.\n\nSo if a malicious userspace task with access to the root hub via\n/dev/bus/usb/.../001 issues a USBDEVFS_CONTROL ioctl with `wValue`\ngreater than or equal to 32, the left shift operation invokes\nshift-out-of-bounds undefined behavior. This results in arbitrary\nbit corruption of `port_status`, including the normally-immutable\nchange bits, which can bypass internal state checks and confuse the\nhub status.\n\nFix this by rejecting requests whose `value` exceeds the shift width\nbefore performing the shift.\n\nThis issue was found using a KLEE-based symbolic execution tool for\nkernel drivers that I'm currently developing."
    }
  ],
  "lastModified": "2026-08-17T06:19:16.463",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}