Executive brief
A vulnerability in the Linux kernel's USB serial driver for ZyXEL omni.net devices could allow a malicious USB device to cause memory corruption. By plugging in a specially crafted device that reports unexpected data sizes, an attacker could potentially crash the system or execute unauthorized code. This issue primarily affects systems where untrusted physical USB devices can be connected.
Technical details
A vulnerability exists in 'drivers/usb/serial/omninet.c' within the Linux kernel due to insufficient validation of USB endpoint descriptors. The driver uses a hardcoded transfer size for bulk-out buffers without ensuring the buffers are at least as large as the reported max packet size from the device. A malicious USB device can report a smaller-than-expected max packet size to trigger user-controlled slab corruption. This is a physical attack vector requiring the connection of a crafted USB device. Patches have been released across multiple stable kernel branches to enforce a minimum 'bulk_out_size'.
Affected products
- Linux Linux 2.6.12 through 6.6.x
Timeline
- 2026-05-22: patched: Initial patch authored by Johan Hovold
- 2026-07-19: advisory: CVE published to NVD dataset
References
- https://git.kernel.org/stable/c/0bda1893e4cc4ad2b7dcdbaca246f2af688c6c2a
- https://git.kernel.org/stable/c/0fee0ccac29e088d4bfab7e2d075725dcecd803d
- https://git.kernel.org/stable/c/180996f0ca774001944e4afa452d569ba2f6455c
- https://git.kernel.org/stable/c/4e7d32189d6219beb7db37cd0ea36b6bac7dfedb
- https://git.kernel.org/stable/c/60df93d30f9bdd27db17c4d80ed80ef718d7226b
- https://git.kernel.org/stable/c/9a3860454bdfb765f936965e975c594352602ffc
- https://git.kernel.org/stable/c/b496e25ead5976bce2891dacaed09beb53a54f9f