« Volver al listado

CVE-2026-80827

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

USB: serial: option: fix slab OOB read in interrupt URB callback

The interrupt URB buffer is allocated in setup_port_interrupt_in() based on the endpoint's wMaxPacketSize:

When a USB device declares wMaxPacketSize = 8 on its interrupt IN endpoint, the buffer is allocated from kmalloc-8 cache (exactly 8 bytes).

If the device sends a short packet (actual_length < wMaxPacketSize), the URB completes with status == 0 and the callback proceeds to read:

which evaluates to data[8], accessing 1 byte beyond the allocated 8-byte buffer. This results in a slab out-of-bounds read.

Leer descripción completaMostrar menos

Fix this by adding the missing bounds check: first verify that the actual length is large enough to contain the struct usb_ctrlrequest header before accessing req_pkt->bRequestType and req_pkt->bRequest, and then verify that there is an additional byte for the modem signal state before reading data[sizeof(struct usb_ctrlrequest)] inside the conditional. Use sizeof(*req_pkt) instead of sizeof(struct usb_ctrlrequest) for consistency.

[ johan: use dev_err(); split signals declaration and initialisation ]

Detalles técnicos trazas, registros y código del informe original
    buffer_size = usb_endpoint_maxp(epd);
    port->interrupt_in_buffer = kmalloc(buffer_size, GFP_KERNEL);

    data[sizeof(struct usb_ctrlrequest)]

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80827",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "58cfe9113e485f7e04bd0eac4fc4251b330af501",
              "lessThan": "fbe60fd2abc8a5561f39719a41ad9a01b5d8e567",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "58cfe9113e485f7e04bd0eac4fc4251b330af501",
              "lessThan": "94e5525697b9e91ddc4071129874120a50a4f342",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "58cfe9113e485f7e04bd0eac4fc4251b330af501",
              "lessThan": "6b8cf5422c7e96ed5b22a8368eff663f3f98b8ec",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "58cfe9113e485f7e04bd0eac4fc4251b330af501",
              "lessThan": "030e3a73d3c3aa67c44454649e984d6383cdb7d3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "58cfe9113e485f7e04bd0eac4fc4251b330af501",
              "lessThan": "060db7d48af1e650643c8b8319111a9ea2ce4486",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "58cfe9113e485f7e04bd0eac4fc4251b330af501",
              "lessThan": "2ef5560387f2c0713cee975be2b24b281bd90f3e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "58cfe9113e485f7e04bd0eac4fc4251b330af501",
              "lessThan": "a72a13c83a652516a0e469d275b81d29a7429049",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "58cfe9113e485f7e04bd0eac4fc4251b330af501",
              "lessThan": "d762aef4eba354066be21a5d88eb2066e282f4c9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "58cfe9113e485f7e04bd0eac4fc4251b330af501",
              "lessThan": "885d802f544ca7bfa8f3984d94233cce715bb6b3",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/usb/serial/option.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.12"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "2.6.12",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.269",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.220",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.187",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.156",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.108",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.49",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.13",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.3",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/usb/serial/option.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-04T16:18:10.683",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/030e3a73d3c3aa67c44454649e984d6383cdb7d3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/060db7d48af1e650643c8b8319111a9ea2ce4486",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2ef5560387f2c0713cee975be2b24b281bd90f3e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6b8cf5422c7e96ed5b22a8368eff663f3f98b8ec",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/885d802f544ca7bfa8f3984d94233cce715bb6b3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/94e5525697b9e91ddc4071129874120a50a4f342",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a72a13c83a652516a0e469d275b81d29a7429049",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d762aef4eba354066be21a5d88eb2066e282f4c9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fbe60fd2abc8a5561f39719a41ad9a01b5d8e567",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: option: fix slab OOB read in interrupt URB callback\n\nThe interrupt URB buffer is allocated in setup_port_interrupt_in() based\non the endpoint's wMaxPacketSize:\n\n    buffer_size = usb_endpoint_maxp(epd);\n    port->interrupt_in_buffer = kmalloc(buffer_size, GFP_KERNEL);\n\nWhen a USB device declares wMaxPacketSize = 8 on its interrupt IN\nendpoint, the buffer is allocated from kmalloc-8 cache (exactly\n8 bytes).\n\nIf the device sends a short packet (actual_length < wMaxPacketSize),\nthe URB completes with status == 0 and the callback proceeds to read:\n\n    data[sizeof(struct usb_ctrlrequest)]\n\nwhich evaluates to data[8], accessing 1 byte beyond the allocated 8-byte\nbuffer. This results in a slab out-of-bounds read.\n\nFix this by adding the missing bounds check: first verify that the\nactual length is large enough to contain the struct usb_ctrlrequest\nheader before accessing req_pkt->bRequestType and req_pkt->bRequest,\nand then verify that there is an additional byte for the modem signal\nstate before reading data[sizeof(struct usb_ctrlrequest)] inside the\nconditional.  Use sizeof(*req_pkt) instead of sizeof(struct\nusb_ctrlrequest) for consistency.\n\n[ johan: use dev_err(); split signals declaration and initialisation ]"
    }
  ],
  "lastModified": "2026-09-04T16:18:10.683",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}