Executive brief
A vulnerability in the Linux kernel's USB driver could allow a local user to trigger an out-of-bounds memory read. This occurs when the system processes specific USB device descriptors, potentially leading to a system crash or the exposure of sensitive kernel memory. The issue affects a wide range of Linux distributions and kernel versions.
Technical details
An out-of-bounds (OOB) read vulnerability exists in the `usb_parse_ss_endpoint_companion()` function within `drivers/usb/core/config.c`. The root cause is that the function validates the descriptor type field before verifying that the buffer is large enough to contain the descriptor. By providing a malformed USB descriptor where the reported size is smaller than the expected `USB_DT_SS_EP_COMP_SIZE`, an attacker can trigger a read outside the intended buffer boundaries. This is a local attack vector requiring the ability to interface with USB configuration parsing. Patches have been released across multiple stable kernel branches to ensure the size check occurs before field access.
Affected products
- Linux Linux Kernel 2.6.35 to 5.10.241, 5.11 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.43, 6.13 to 6.15.11, 6.16 to 6.16.2
Timeline
- 2025-09-11: disclosed
- 2025-08-28: patched: Patched in various stable branches by Greg Kroah-Hartman
- 2025-09-11: advisory
References
- https://git.kernel.org/stable/c/058ad2b722812708fe90567875704ae36563e33b
- https://git.kernel.org/stable/c/4fe6f472f0beef4281e6f03bc38a910a33be663f
- https://git.kernel.org/stable/c/5badd56c711e2c8371d1670f9bd486697575423c
- https://git.kernel.org/stable/c/5c3097ede7835d3caf6543eb70ff689af4550cd2
- https://git.kernel.org/stable/c/9512510cee7d1becdb0e9413fdd3ab783e4e30ee
- https://git.kernel.org/stable/c/9843bcb187cb933861f7805022e6873905f669e4
- https://git.kernel.org/stable/c/b10e0f868067c6f25bbfabdcf3e1e6432c24ca55