Junglewise Threat Intelligence

CVE-2026-63898: Linux Kernel memory corruption in MCT U232 USB serial driver

CVE-2026-63898 · Severity: info · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's USB serial driver for MCT U232 devices could allow a malicious USB device to cause memory corruption. By reporting an unexpectedly small data packet size, a rogue device can trigger a crash or potentially execute unauthorized code on the connected system. This issue primarily affects systems where untrusted physical USB devices can be inserted.

Technical details

A memory corruption vulnerability exists in the mct_u232 USB serial driver (drivers/usb/serial/mct_u232.c) due to improper handling of the maximum transfer size. The driver previously overrode the bulk-out endpoint size to 16 bytes for specific hardware (Sitecom U232-P25) without verifying if the device actually reported a smaller size. An attacker with physical access can provide a malicious USB device that reports an endpoint size smaller than the driver's hardcoded override, leading to slab corruption during data transfers. The fix implements a 'min()' check to ensure the transfer size is never increased beyond what the device reports. Patching is available in various stable kernel branches (e.g., 5.10.259, 5.15.210, 6.1.176).

Affected products

  • Linux Linux Kernel 2.6.12 to 6.6.143

Timeline

  • 2026-06-19: patched: Fix committed to stable kernel tree.
  • 2026-07-19: disclosed: CVE published.

References

Related threats