Junglewise Threat Intelligence

CVE-2026-31607: Linux Kernel heap out-of-bounds write in usbip_pack_ret_submit

CVE-2026-31607 · Severity: critical · CVSS 9.8 · Published 2026-04-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's USB/IP implementation allows a malicious server to crash or potentially take control of a client system. USB/IP is a feature that allows USB devices to be shared over a network. By sending a specially crafted response, an attacker can trigger a memory corruption error on the connected client, leading to system instability or unauthorized data access.

Technical details

A heap out-of-bounds write vulnerability exists in the Linux kernel's usbip driver within the usbip_pack_ret_submit() function. When a USB/IP client receives a RET_SUBMIT response, the driver unconditionally overwrites the 'number_of_packets' field from the network PDU. This value is later used as a loop bound in usbip_recv_iso() to iterate over the 'iso_frame_desc' array, which has a fixed size determined at allocation time. A malicious server can provide a 'number_of_packets' value larger than the original request, leading to a write beyond the allocated buffer. The fix involves validating the response value against the original URB allocation size and clamping it to zero if it exceeds the limit.

Affected products

  • Linux Linux Kernel 2.6.39 to 6.6.136, 6.7 to 6.12.83, 6.13 to 6.18.24, 6.19 to 6.19.14, 7.0 to 7.0.1

Timeline

  • 2026-04-02: other: Patch authored
  • 2026-04-24: advisory: CVE published

References