Executive brief
A vulnerability in the Linux kernel's USB/IP implementation allows a malicious server to crash or potentially take control of a client system. USB/IP is a feature that allows USB devices to be shared over a network. By sending a specially crafted response, an attacker can trigger a memory corruption error on the connected client, leading to system instability or unauthorized data access.
Technical details
A heap out-of-bounds write vulnerability exists in the Linux kernel's usbip driver within the usbip_pack_ret_submit() function. When a USB/IP client receives a RET_SUBMIT response, the driver unconditionally overwrites the 'number_of_packets' field from the network PDU. This value is later used as a loop bound in usbip_recv_iso() to iterate over the 'iso_frame_desc' array, which has a fixed size determined at allocation time. A malicious server can provide a 'number_of_packets' value larger than the original request, leading to a write beyond the allocated buffer. The fix involves validating the response value against the original URB allocation size and clamping it to zero if it exceeds the limit.
Affected products
- Linux Linux Kernel 2.6.39 to 6.6.136, 6.7 to 6.12.83, 6.13 to 6.18.24, 6.19 to 6.19.14, 7.0 to 7.0.1
Timeline
- 2026-04-02: other: Patch authored
- 2026-04-24: advisory: CVE published
References
- https://git.kernel.org/stable/c/2ab833a16a825373aad2ba7d54b572b277e95b71
- https://git.kernel.org/stable/c/324262c38438255bf6bdbf6342ca47c0badaab76
- https://git.kernel.org/stable/c/5e1c4ece08ccdc197177631f111845a2c68eede3
- https://git.kernel.org/stable/c/885c8591784da6314f9aa82fa460ac69f9f79e5f
- https://git.kernel.org/stable/c/8d155e2d1c4102f74f82a2bf9c016164bb0f7384
- https://git.kernel.org/stable/c/906f16a836de13fe61f49cdce2f66f2dbd14caf4
- https://git.kernel.org/stable/c/973f2c250289f5bf6cc146b98aa6fdde11fe50d6