Executive brief
A vulnerability in the Linux kernel's USB printer driver could allow a malicious or malfunctioning USB device to leak sensitive information from the computer's memory. By sending a specially crafted response during identification, a device can trick the system into revealing up to 1021 bytes of previously used internal memory. This could potentially expose fragments of data from other applications or system processes to a local user or the connected device.
Technical details
A vulnerability exists in the usblp_cache_device_id_string() function within the Linux kernel's USB printer driver (drivers/usb/class/usblp.c). The driver fails to verify the actual number of bytes transferred during a GET_DEVICE_ID control request and trusts a length prefix provided by the device. If a device sends a 'short' response but claims a large length, the driver leaves the remainder of the 1024-byte kmalloc buffer uninitialized. This stale heap data is subsequently exposed to userspace through the ieee1284_id sysfs attribute and the IOCNR_GET_DEVICE_ID ioctl. The fix involves zeroing the buffer with memset() before initiating the USB control message.
Affected products
- Linux Linux Kernel All versions prior to the May 2026 patches
Timeline
- 2026-04-20: patched: Initial patch authored by Greg Kroah-Hartman
- 2026-05-28: advisory: CVE-2026-46151 published
References
- https://git.kernel.org/stable/c/522d17e93a85575256894212d10e5a1fa6f36529
- https://git.kernel.org/stable/c/6d8142141c942c0d8e79343cffda9c44bb1f3f4f
- https://git.kernel.org/stable/c/6e29c32a27218f2dcd4a4e9b0b3c5e7728640698
- https://git.kernel.org/stable/c/7a400c6fe3617e31e690e3f7ca37bb335e0498f3
- https://git.kernel.org/stable/c/8247f52d822180e94ccbfdab91613af386a4e34d