Junglewise Threat Intelligence

CVE-2026-63897: Linux Kernel information leak in MCT U232 USB serial driver

CVE-2026-63897 · Severity: info · CVSS 4.3 · Published 2026-07-19

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's MCT U232 USB-to-serial driver could allow an attacker with physical access to the system to view sensitive information. By plugging in a specially crafted USB device, an attacker could cause the system to leak fragments of internal memory that might contain passwords or other private data. This issue affects systems using older USB-to-serial adapters.

Technical details

A missing sanity check in the 'mct_u232_read_int_callback' function in 'drivers/usb/serial/mct_u232.c' allows for an information leak. The driver fails to verify that 'interrupt-in' transfers contain at least 2 bytes of data before processing them. If a short packet is received, the driver may parse and subsequently leak stale or uninitialized slab data from the kernel's memory to user space. This requires a malicious or malfunctioning USB device to be physically connected to the system. Patches have been released across multiple stable kernel branches to enforce a minimum length check on incoming URBs (USB Request Blocks).

Affected products

  • Linux Linux 2.6.12 through 5.10.258, 5.15.209, 6.1.175, 6.6.142

Timeline

  • 2026-05-20: patched: Initial fix authored by Johan Hovold
  • 2026-07-19: disclosed: CVE-2026-63897 published

References