Executive brief
A vulnerability in the Linux kernel's USB serial driver for MCT U232 devices could allow a malicious USB device to cause memory corruption. By reporting an unexpectedly small data packet size, a rogue device can trigger a crash or potentially execute unauthorized code on the connected system. This issue primarily affects systems where untrusted physical USB devices can be inserted.
Technical details
A memory corruption vulnerability exists in the mct_u232 USB serial driver (drivers/usb/serial/mct_u232.c) due to improper handling of the maximum transfer size. The driver previously overrode the bulk-out endpoint size to 16 bytes for specific hardware (Sitecom U232-P25) without verifying if the device actually reported a smaller size. An attacker with physical access can provide a malicious USB device that reports an endpoint size smaller than the driver's hardcoded override, leading to slab corruption during data transfers. The fix implements a 'min()' check to ensure the transfer size is never increased beyond what the device reports. Patching is available in various stable kernel branches (e.g., 5.10.259, 5.15.210, 6.1.176).
Affected products
- Linux Linux Kernel 2.6.12 to 6.6.143
Timeline
- 2026-06-19: patched: Fix committed to stable kernel tree.
- 2026-07-19: disclosed: CVE published.
References
- https://git.kernel.org/stable/c/39e295a91e80f3b91f61c7ada2bde434dcaba20d
- https://git.kernel.org/stable/c/57f332af1745014cd7e40414814ffaa6bc7d3b5b
- https://git.kernel.org/stable/c/6cb48f8890f9b2051d7c34823057296a536a31c5
- https://git.kernel.org/stable/c/90dbad14b109e5fdfb4934ff61e561d11ba3742d
- https://git.kernel.org/stable/c/915b36d701950503c4ea0f6e314b10868e59fce3
- https://git.kernel.org/stable/c/94edbbc5fe00d03cfe1d4e690d7d2cd36317a935
- https://git.kernel.org/stable/c/bd2ddb3fe9052ad8703593bbec26ecc7ca92869e