« Volver al listado

CVE-2026-89622

Estado: RecibidaAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

HID: mcp2221: clear rxbuf after I2C/SMBus transfer completes

mcp_i2c_smbus_read() stores the caller-supplied buffer pointer in mcp->rxbuf for the duration of a transfer but never clears it when the transfer finishes or times out. Once the caller frees or reuses the buffer, mcp->rxbuf becomes a dangling pointer. A delayed or spurious MCP2221_I2C_GET_DATA report can then drive mcp2221_raw_event() to memcpy device data into the freed memory, causing a write use-after-free.

Route all return paths through a single exit point that clears mcp->rxbuf and mcp->rxbuf_size, so that the existing !mcp->rxbuf guard in the raw_event handler can reject any report arriving after the transfer has ended.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad local (AV:L, PR:L) sin interacción en kernel Linux que permite escritura en memoria liberada. Escalada de privilegios y corrupción de datos mediante carrera temporal en controlador HID.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89622",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "67a95c21463d066060b0f66d65a75d45bb386ffb",
              "lessThan": "d6c6b293173c0ea87189501cbd77e8fa677814a1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "67a95c21463d066060b0f66d65a75d45bb386ffb",
              "lessThan": "03c34309eb1bce1b3b5f7c4a94b703f419120383",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "67a95c21463d066060b0f66d65a75d45bb386ffb",
              "lessThan": "968546b676d992dd1da3e057d40598231f725996",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "67a95c21463d066060b0f66d65a75d45bb386ffb",
              "lessThan": "db2333f88729c8aae062cb171ed058725ff5c901",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/hid/hid-mcp2221.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.7"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.7",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.51",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/hid/hid-mcp2221.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-11T20:19:47.517",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/03c34309eb1bce1b3b5f7c4a94b703f419120383",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/968546b676d992dd1da3e057d40598231f725996",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d6c6b293173c0ea87189501cbd77e8fa677814a1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/db2333f88729c8aae062cb171ed058725ff5c901",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: mcp2221: clear rxbuf after I2C/SMBus transfer completes\n\nmcp_i2c_smbus_read() stores the caller-supplied buffer pointer in\nmcp->rxbuf for the duration of a transfer but never clears it when the\ntransfer finishes or times out. Once the caller frees or reuses the\nbuffer, mcp->rxbuf becomes a dangling pointer. A delayed or spurious\nMCP2221_I2C_GET_DATA report can then drive mcp2221_raw_event() to\nmemcpy device data into the freed memory, causing a write\nuse-after-free.\n\nRoute all return paths through a single exit point that clears\nmcp->rxbuf and mcp->rxbuf_size, so that the existing !mcp->rxbuf guard\nin the raw_event handler can reject any report arriving after the\ntransfer has ended."
    }
  ],
  "lastModified": "2026-09-21T14:17:23.960",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}