Executive brief
A vulnerability in the Linux kernel's Thunderbolt driver could allow a connected device to cause a system crash or read sensitive information from memory. This occurs when the system processes specially crafted Thunderbolt XDomain network packets without properly verifying their size. This issue primarily affects systems with Thunderbolt ports when interacting with other connected Thunderbolt-enabled computers or devices.
Technical details
An out-of-bounds read vulnerability exists in the Linux kernel Thunderbolt driver's XDomain implementation (drivers/thunderbolt/xdomain.c). The function tb_xdp_handle_request() performs type casting of received packet buffers into protocol-specific structures (such as tb_xdp_properties or tb_xdp_link_state_change) without verifying that the actual packet length matches the expected structure size. An adjacent peer can send a truncated XDomain packet that passes initial header checks but triggers an out-of-bounds read during subsequent structure access. This has been resolved by plumbing the packet length through the request work queue and validating it before each cast.
Affected products
- Linux Linux Kernel 4.15 to 7.1
Timeline
- 2026-06-25: disclosed
- 2026-06-25: advisory
References
- https://git.kernel.org/stable/c/07cd2787cdf8942d24a1a3ef81aa89b526fb6381
- https://git.kernel.org/stable/c/0dd61ba03d05187726ecdf9c0e2175a81b9b24f6
- https://git.kernel.org/stable/c/46da5c3ea011e884028a91cf913db093920a915b
- https://git.kernel.org/stable/c/79235c8add5da4bf27a12f5a5dbb579f300c059e
- https://git.kernel.org/stable/c/a504b9f2797b739e0304d537e8aa4ce883ecce39
- https://git.kernel.org/stable/c/a770e62923090d7572f1f5a8507ae551d354a057